1
SAFEGUARDING PRIVACY IN THE DIGITAL AGE: PERSONAL
DATA PROTECTION IN UNITED STATES
Introduction
In the digital era, the development of information and communication technology has
brought great changes to people's lives. In the process, personal data has become
increasingly important and sensitive as many activities are conducted online. Personal data
includes information such as name, address, identity number, financial information, medical
history, and other sensitive information relating to individuals.
In the midst of the rapid digital era, individuals' personal data is increasingly
vulnerable to potential misuse and privacy violations. Personal data security is a human right
that must be guaranteed and respected. United States, as a developing country with rapid
technology adoption, has the responsibility to protect personal data as a right to privacy. In
this context, the right to privacy is an urgent issue to be addressed. The right to privacy is
the fundamental right of every individual to maintain the confidentiality and security of their
personal data. With increasing cases of privacy violations and misuse of personal data, it is
important for every country to have effective laws and regulations to protect the privacy
rights of its citizens.
In United States, awareness of the need for personal data protection has been
increasing, especially along with the growth of internet usage and technology-based
applications. The right to self-defense is one of the legal rights outlined in the 1945
Constitution. According to Article 28G Paragraph (1), citizens are entitled to the protection
of themselves, their families, honor, dignity, and property. However, with the advancement
of information and communication technology, personal rights should not only be
understood as property rights as stipulated in the article. The right to privacy should be a
fundamental one. Since it deals with a person's personal information or identity, the right to
privacy is more sensitive and can be seen as a personal right. But recent examples of
personal data leaks have been a severe problem. Some of them consist of 1:
The Tokopedia case (2020): In early 2020, a major United States e-commerce
platform, Tokopedia, reportedly suffered a security breach that resulted in the personal
information of millions of users being leaked. The compromised data included names,
2
addresses, phone numbers, email addresses, and encrypted passwords.
Bukalapak case (2021): Bukalapak, another e-commerce platform in United States,
also reportedly suffered a data breach in 2021. More than 13 million user accounts
were reportedly affected, with data such as usernames, email addresses, phone
numbers, and passwords leaked.
TokoTalk case (2021): In 2021, United States instant messaging app TokoTalk was
also reported to have suffered a data leak. More than 91 million accounts affected
users, and the leaked information includes names, phone numbers, email addresses,
and copies of identification cards.
Personal data leakage is a serious problem that can lead to financial losses, false
identities, and even further misuse of data. Governments, companies, and individuals need to
raise awareness about data security and take proper precautionary measures to protect
personal data. It is important to keep abreast of the latest news to understand the latest
developments on data security issues in United States or in any country.
In today's digital era, almost every device is connected and has internet connection,
everything can be managed from anywhere. When people use digital technology in their
daily lives to improve work efficiency, create socio-economic relationships, and facilitate
other activities, the consequences of this period are enormous.2 Computer-based technology
for information and communication has developed rapidly in society. These technological
advances then help society.
Although scattered across various laws, personal data protection safeguards exist in
United States. United States current Personal Data Protection Bill (PDT Bill) needs to be
studied in more detail as the regulation still needs improvement. At least United States can
be compared to other countries' personal data protection laws, such as in Hong Kong,
Malaysia, Singapore and South Korea. Legal protection of personal data is already
guaranteed by specific laws in some of these countries, but in this study, we will compare
Malaysia's personal data protection law with United States PDT bill. The Personal Data
Protection Bill has important objectives and benefits in the context of protecting the privacy
and use of personal data in United States, and aims to create a digital environment that is
more secure, trusted, and respectful of individual privacy, while still enabling economic
3
growth and innovation in the digital era.
With the variety of legal systems, the principle of universality can be used, especially
for the benefit of global interests based on the assumption that every nation in the world
must participate in implementing the global legal system. Based on the phenomenon and
misuse of privacy data above, the researcher is interested in examining how the principle of
the right to privacy against personal data and whether United States responsibility for
personal data as a right to privacy through legislation.
Research Methods
This research uses a conceptual approach, namely the approach. A conceptual
approach is a form of approach used in legal research that offers a point of view for
analyzing the following problem from the perspective of the underlying legal concept, or
even from the values contained in the normalization of a regulation in relation to other
concepts used.
Results and Discussion
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
4
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
5
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
6
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
7
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
8
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
9
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
10
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
11
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
12
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
13
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
14
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
15
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
16
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
17
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
18
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
19
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
20
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
21
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
22
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
23
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
24
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
25
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
26
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
27
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
28
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
29
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
30
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
31
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
32
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
33
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
34
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
35
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
36
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
37
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
38
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
39
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
40
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
41
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
42
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
43
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
44
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
45
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
46
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
47
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
48
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
49
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
50
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
51
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
52
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
53
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
54
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
55
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
56
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
57
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
58
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
59
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
60
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
61
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
62
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
63
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
64
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
65
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
66
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
67
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
68
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
69
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
70
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
71
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
72
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
73
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
74
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
75
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
76
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
77
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
78
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
79
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
80
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
81
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
82
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
83
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
84
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
85
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
86
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
87
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
88
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
89
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
90
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
91
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
92
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
93
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
94
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
95
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
96
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
97
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
98
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
99
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
100
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
101
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
102
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
103
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
104
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
105
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
106
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
107
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
108
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
109
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
110
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
111
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
112
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
113
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
114
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
115
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
116
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
117
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
118
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
119
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
120
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
121
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
122
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
123
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
124
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
125
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
126
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
127
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
128
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
129
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
130
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
131
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
132
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
133
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
134
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
135
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
136
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
137
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
138
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
139
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
140
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
141
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
142
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
143
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
144
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
145
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
146
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
147
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
148
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
149
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
150
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
151
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
152
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
153
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
154
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
155
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
156
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
157
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
158
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
159
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
160
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
161
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
162
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
163
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
164
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
165
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
166
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
167
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
168
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
169
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
170
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
171
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
172
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
173
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
174
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
175
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
176
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
177
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
178
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
179
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
180
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
181
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
182
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
183
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
184
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
185
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
186
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
187
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
188
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
189
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
190
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
191
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
192
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
193
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
194
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
195
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
196
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
197
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
198
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
199
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
200
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
201
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
202
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
203
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
204
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
205
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
206
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
207
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
208
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
209
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
210
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
211
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
212
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
213
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
214
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
215
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
216
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
217
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
218
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
219
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
220
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
221
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
222
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
223
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
224
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
225
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
226
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
227
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
228
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
229
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
230
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
231
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
232
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
233
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
234
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
235
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
236
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
237
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
238
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
239
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
240
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
241
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
242
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
243
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
244
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
245
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
246
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
247
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
248
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
249
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
250
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
251
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
252
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
253
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
254
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
255
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
256
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
257
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
258
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
259
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
260
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
261
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
262
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
263
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
264
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
265
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
266
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
267
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
268
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
269
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
270
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
271
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
272
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
273
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
274
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
275
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
276
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
277
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
278
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
279
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
280
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
281
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
282
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
283
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
284
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
285
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
286
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
287
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
288
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
289
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
290
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
291
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
292
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
293
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
294
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
295
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
296
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
297
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
298
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
299
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
300
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
301
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
302
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
303
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
304
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
305
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
306
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
307
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
308
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
309
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
310
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
311
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
312
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
313
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
314
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
315
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
316
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
317
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
318
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
319
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
320
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
321
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
322
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
323
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
324
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
325
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
326
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
327
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
328
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
329
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
330
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
331
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
332
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
333
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
334
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
335
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
336
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
337
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
338
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
339
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
340
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
341
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
342
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
343
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
344
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
345
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
346
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
347
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
348
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
349
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
350
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
351
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
352
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
353
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
354
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
355
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
356
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
357
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
358
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
359
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
360
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
361
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
362
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
363
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
364
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
365
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
366
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
367
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
368
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
369
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
370
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
371
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
372
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
373
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
374
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
375
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
376
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
377
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
378
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
379
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
380
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
381
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
382
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
383
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.
Principle of the Right to Privacy of Personal data
The principle of the right to privacy of personal data is a critical aspect in this
increasingly advanced digital era. Every day, we interact with technology and provide
personal data online. Personal data refers to any information that can directly or indirectly
identify an individual. This includes, but is not limited to, name, address, phone number,
email address, date of birth, identification number, financial data, and medical information.4
However, by providing this information, we also open up opportunities for potential data
misuse and privacy violations.
The right to privacy of personal data includes the right of every individual to know what
happens to their personal data, who accesses it, for what purposes it is used, and how it is
processed and stored. Moreover, this principle also involves the right to give consent to the
use of personal data, as well as the right to request deletion of data (right to be forgotten) or
correction if the data is inaccurate.
The principle of the right to privacy in personal data aims to protect the human rights
and dignity of individuals, and to ensure that personal data is used with ethics and honesty.
This is relevant not only for companies that collect data, but also for governments and other
entities involved in the collection, processing and use of personal data.5 Some examples of
cases of violated or perceived violated privacy rights that have existed in United States are
the leak of personal data on BPJS health services in 2021, In 2020, there was a data breach
on the e-commerce platform Tokopedia. The personal data of tens of millions of users,
including names, email addresses, phone numbers, and other information, and what is still
unclear is that the personal data of users of online transportation applications such as Gojek
or Grab has been leaked due to a security breach.
The right to privacy, sometimes known as the right not to be disturbed, was coined by
Warren and Brandheis and published in a manuscript titled "The Right to Privacy" in
384
Harvard University Law School's scholarly journal. According to Warren and Brandheis in
the journal, the growth and development of technology has led to public awareness that
everyone has the right to enjoy life. "Privacy is the right to enjoy life and the right to be left
alone, and this legal development is inevitable and demands legal recognition," Warren and
Brandeis said. Everyone has the right to enjoy his or her privacy, which requires it to be
safeguarded.
According to Warren and Brandheis, along with the development and advancement of
technology, people's awareness has grown, leading to the realization that everyone has the
right to enjoy life. "Privacy is the right to enjoy life and the right to be left alone, and this
legal development is inevitable and demands legal recognition," Warren and Brandeis said.
Everyone has the right to enjoy his privacy, which requires that it be safeguarded.
First and foremost, maintaining relationships with others requires a person to hide some
aspects of his or her personal life in order to maintain his or her position to a certain degree.
Secondly, privacy is a right that stands alone and does not depend on other rights, but this
right will be lost if the person reveals private items to the public. Third, a person in his life
needs time to be alone, so privacy is needed by a person. Fourth, the right to privacy
includes a person's ability to maintain domestic relationships, such as how they support their
marriage and maintain their family. Warren further describes this as the right against words.
Fifth, the inability to calculate damages is another reason why privacy needs legal
protection. Because it has interfered with his private life, his perceived loss is much greater
than the actual loss, and as a result the victim should be compensated for any loss.
The Constitution and relevant laws and regulations serve as the foundation of United
States law. Every person has the right to protect himself, his family, honor, dignity, and
property under his control, according to the 1945 Constitution, and is entitled to a sense of
security and tranquility from danger and fear. Article 28 Letter G Paragraph (1) of the 1945
Constitution specifically stipulates that "Every person shall have the right to protection of
self, family, honor, dignity, and property under his control, and shall have the right to a
sense of security and to be protected from the threat of fear of crime." or fail to exercise
human rights." The idea of data protection protects people's freedom to choose whether or
not to disclose or exchange their personal data. In addition, people have the right to choose
requirements for the transfer of such personal data. To create the right to protect personal
385
data, the right to privacy has evolved.
Every individual can choose to privacy their data or share it, and this freedom is
protected by the laws that apply in United States. 9 Based on this legal basis, United States
citizens have a constitutional right to the protection of their privacy rights, which includes
the right to privacy of their personal information. The state is obliged under its constitutional
rights to provide legal protection for various aspects of the lives of United States citizens.
The legal objectives for constitutional rights should include legal benefits, justice and
clarity.
In relation to the protection of personal data, some of the measures or efforts that have
been taken by the Government of United States are:
Law Number 11 of 2020 concerning Electronic Information and Transactions (UU ITE)
Although more focused on electronic transactions and information security, the ITE
Law also has provisions related to the protection of personal data in electronic systems.
This law requires data managers to protect personal data and provides sanctions for
violations that harm privacy rights.
Drafting of Personal Data Protection Bill The United States government has drafted a
law that specifically regulates the protection of personal data. Although this bill has not
yet been passed into law to the best of my knowledge, this move demonstrates the
government's efforts to address personal data protection more comprehensively.
Minister of Communication and Informatics Regulation No. 20/2016 on Personal Data
Protection in Electronic Systems
This regulation governs the protection of personal data in electronic systems and
provides guidelines on proper practices in the management of personal data.
Sectoral Personal Data Protection Arrangements
Some sectors, such as banking, healthcare and telecommunications, have their own
regulations or guidelines regarding personal data protection. For example, Bank United
States has regulations regarding the protection of customer personal data.
Supervision and Sanctions
The government also has a role in overseeing entities that manage personal data. In the
event of a violation, they can sanction the perpetrators who violate the data protection
provisions.
386
Public Awareness Campaign
The government has also conducted campaigns to raise public awareness on the
importance of protecting personal data and safe practices in sharing personal
information.
Data Security Framework Development
Governments have sought to develop data security frameworks that assist organizations
and companies in protecting the personal data they manage.
International Cooperation
The United States government also engages in international cooperation in the field of
personal data protection, including complying with recognized international standards.
The technical efforts made by the government to date in protecting the personal data of
its citizens include:
System Security Enhancement
Governments can apply high security standards to the systems and infrastructure that
manage personal data. This includes the use of data encryption, protection against
cyberattacks, and the implementation of strong firewalls.
Anomalous Activity Monitoring
Governments can use monitoring tools to detect suspicious anomalous activity on a
system or network. This can help detect hacking attempts or unauthorized access.
Security Certification
The government can issue security certifications to organizations or services that
manage personal data, once they are proven to meet certain security standards.
Security Auditor
The government may employ or engage independent security auditors to conduct
regular audits of systems and practices relating to the protection of personal data.
Regulation of the Obligation to Report Violations
Governments can require organizations to report personal data breaches immediately to
the competent authority, so that swift action can be taken to minimize the impact.
Employee Training
The government can encourage organizations to provide training to employees on data
security practices, such as how to recognize phishing or secure passwords.
Segregation of Sensitive Data
387
Sensitive personal data may be isolated or separated from other data to reduce the risk
of unauthorized access.
Access Security
The government can encourage the implementation of dual authentication or limited
access mechanisms to avoid unauthorized access to personal data.
Data Protection During Transit
The government can encourage the use of encryption while data is in transit between
sender and receiver, for example through the HTTPS protocol.
Safe handling of unused data
The government can provide guidelines for organizations on how data that is no longer
needed should be securely deleted or destroyed.
Security Testing
Governments can encourage organizations to regularly conduct security testing, such as
penetration tests, to identify vulnerabilities.
Cooperation with the Security Industry
The government can work with cybersecurity companies and researchers to understand
the latest threat trends and implement preventive measures accordingly.
United States Responsibility for Personal Data as a Right to Privacy through Laws and
Regulations
Protection of personal data has been carried out by several other countries such as
Singapore, Malaysia, Hong Kong, and South Korea. Singapore's Personal Data Protection
Act No. 26 of 2012 (PDPA 2012) provides legal protection for personal data in Singapore.
Several guiding principles for the legal protection of personal data are outlined in
Singapore's PDPA 2012. The concept of "deemed consent", or explicitly given consent to be
used for a specific purpose, is recognized by the regulation. Singapore's PDPA 2012 also
provides for civil and criminal consequences, including fines of up to USD 790,000 and/or
imprisonment of up to 3 (three) years.
The Personal Data Protection Act No. 709 of 2010 (PDPA Malaysia) is one of the
existing laws and regulations protecting personal data in Malaysia. To protect the interests of
388
data subjects, the Personal Data Protection Act of 2010 regulates how personal data is
processed by data users in the course of commercial transactions. This is done by ensuring
that data subjects' consent is obtained before any personal data is processed and by
providing them with the ability to view, update and manage the processing of their personal
data. The Personal Data Protection Advisory Committee was established in Malaysia under
the Personal Data Protection Act 2010 with the responsibility of receiving information
regarding threats and data transfer unauthorized personal data.10 PDPA Malaysia has the
following principles for the legal protection of personal data in Sections 5 to 12:
The General Principle of Authorization-based Processing (Article 6), which prohibits data
users from processing personal data without the consent of the data owner.
The general restriction on the processing of personal data is regulated by the following
criteria
"validity, necessity, and not exceeding" (Article 6 Paragraph 3).
Principles of collection and notification. The data owner must be aware of and give consent
for the acquisition of personal data, and the data user must inform the data user in writing of
the reasons for the collection of personal data.
Guidelines on use and disclosure (paragraph 3 of Section 6). If used and processed for legal
purposes, user data-related purposes, and connected data collection and processing purposes,
personal data may be used and processed.
Sensitive personal data includes information about an individual's health, mental state,
religious beliefs, tort claims, political preferences, and other specific topics.
Security guiding principles. Every data user must comply with this concept in accordance
with the rules laid down by the Commissioner for the protection of personal data.
Data Retention Principles and Right to Block Processing. Since the user's data must comply
with the retention guidelines of the Commissioner for the Protection of Personal Data, he or
she must verify that the personal data has been completely destroyed after the intended
purpose has been fulfilled.
Data Integrity Principle, number 8. Users of personal data can ensure that the data is correct,
current and impossible to access by taking reasonable precautions.
Principle of access and correction. Personal data owners have the right to update and amend
personal information that is outdated, incorrect or incomplete.
Whereas in South Korea the Personal Information Protection Act (PIPA), passed in
389
2011, is a law in South Korea that regulates the protection of personal data. For the sake of
the security of personal information of South Korean citizens, the majority of whom use the
internet, South Korea has developed legislative urgency in terms of data privacy protection.
Article 3 of PIPA 2011 outlines the standards for personal data protection in South Korea.
Personal data processors are required to comply with a number of principles, including:
Set clear and specific goals.
Manage in a way that does not infringe on the rights of data subjects;
Processing personal data for the purpose of collecting personal data only;
Fill in personal data accurately, completely and up-to-date;
Pay attention to personal data security;
Publicize privacy policies and guarantee access rights;
Try to manage data privately without giving the name of the data subject, if possible.
And
Seek to win the trust of data subjects by adhering to the law.
In Hong Kong, the Personal Data Privacy Ordinance 1995 (PDPO), which was
amended in 2012 due to the lack of proper implementation of the principles of the PDPO
1995, already exists in Hong Kong and governs the legal protection of personal data. The
PDPO 2012 sets out the following guidelines for the legal protection of personal data:
Restrictions on Collection of Personal Information. Data collection should not go
beyond the purpose of the collection itself and should have a legitimate purpose, a
connection to the data collector, and both.
Use and disclosure of personal data. Personal data may only be disclosed if it is done
in accordance with the original intention and with the consent of the owner.
Data quality obligations and advice obligations to third parties. Obligation to ensure
data security, delete incorrect data, or not use it during the process.
Erasure and destruction of personal data. When a purpose is achieved, personal data
should not be kept for too long.
Data Security Responsibility. Users of personal data are required to offer guarantees
regarding data security against accidental and unauthorized processing.
Transparency Practices. This idea formed the basis of the Commissioner's decision to
require public disclosure of privacy policies by organizations and legal entities
operating in Hong Kong.
390
The United States government has a responsibility to create and implement adequate
and effective regulations related to personal data. The government should play an active role
in enacting appropriate regulations, providing education and awareness regarding privacy
rights, as well as monitoring and enforcing laws against data privacy violations. Although
United States already has a draft law on personal data protection, it currently does not have
any legislation that specifically regulates personal data protection. On the other hand, United
States currently has several laws and regulations relating to personal data protection, as
follows:
Law No. 10 of 1998 on the Amendment to Law No. 7 of 1992 on Banking
The phrase "bank secrets" is defined as "everything relating to depositors and their
deposits" in Article 1 Paragraph (28) of the Constitution. This clarifies that any customer-
related information in a bank is a sensitive and private matter. Except in the circumstances
referred to in Articles 41, 41A, 42, 44, and 44A, banks are expected to maintain the
confidentiality of information held on depositors and their deposits, in accordance with
Article 40 Paragraph (1). According to this article, banks are obliged to secure all customer
data.
Law Number 36 Year 1999 on Telecommunication
Personal data protection is generally regulated by the Telecommunications Law, although
it is not specifically related to personal data. "Telecommunication service providers are
obliged to keep confidential the information sent and/or received by telecommunication
service customers through telecommunication networks and/or telecommunication services
they provide," Article 42 paragraph 1 of the Telecommunication Law reads. This is the basis
of the service provider's obligation to ensure the security of any data that will be sent
through telecommunications networks or received through telecommunications services. For
the purposes of the criminal justice process, telecommunications service providers can
record information sent and or received by telecommunications service providers and can
provide the information required above:
written request from the Attorney General and/or the Chief of the United States National
Police. Republic of United States for certain criminal offenses;
Written request from the Attorney General and/or the Chief of the United States National
Police;
391
According to Article 57 of the Telecommunication Law, "Telecommunication service
providers who violate the provisions as referred to in Article 42 paragraph (1) shall be
punished with imprisonment for a maximum of 2 (two) years and or a maximum fine of
Rp200,000,000.00 (two hundred million rupiah)." The Telecommunication Law also
regulates sanctions regarding criminal acts against information security.
Law No. 39/1999 on Human Rights (Human Rights Law)
The legislation that regulates a person's human rights is the Human Rights Law.
Everyone has the right to communicate and access the knowledge necessary to develop their
personality and social environment, in accordance with Article 14 Section 1 of the
Constitution. This article affirms that everyone has the right to access the knowledge they
need for daily life in order to advance their own growth and the quality of the environment
in which they live. Article 29 Paragraph (1) of the Human Rights Law states that "Everyone
has the right to protect themselves, family, honor, dignity, and property rights". This article
regulates the right to personal protection guaranteed by Article 28 Letter G Paragraph (1) of
the 1945 Constitution. According to Article 32 of the Human Rights Law, which states that
"Freedom and confidentiality in correspondence relations, including communication
relations by electronic means, shall not be interfered with, except by order of a judge or
other authorized official in accordance with the provisions of the Human Rights Law," there
are also new additions to the law relating to the protection of personal data.
Law No. 19 of 2016 on the Amendment to Law
- Law Number 11 of 2008 concerning Electronic Information and Transactions (UU
ITE)
The only article that explicitly guarantees data protection The ITE Law, specifically Articles
27 to 37, regulates illegal activities in the field of electronic information that are not
specifically related to personal data. . These articles generally prohibit acts that violate rights
and intentional misuse of electronic information that can harm others, especially the owner
of the information.
Following some cases of hacking, Draft Personal Data Protection Bill (RUU PDP),
which the House of Representatives hopes to pass into law, seems to be a breath of fresh air
392
for United Statess. Awareness sector commercial sector, organizations government
organizations, and society is the government's biggest problem in realizing the PDP Law.
The government must ensure that every business and government organization in United
States is able to comply with the PDP Law. Hospitals, public service applications, industrial
banking, and financial businesses are just a few of them.
Because it is possible for those who do not understand the PDP Law to commit
violations without realizing it, training the public to comply with the law is a challenge. The
PDP Law specifically regulates data privacy processes for children and people with
disabilities. However, there is a tendency for all information about children and adults with
disability is abused. The 'special' process mentioned in the PDP Law is not clearly defined,
and there is no age limit for children who are considered as such.
The removal of certain data from the previous bill, which poses the danger of data
attacks to discriminate against certain groups, is one of the issues affecting vulnerable
groups today. By addressing the shortcomings and deficiencies of the PDP Law, the
government is expected to strengthen the protection of children's data and the data of other
groups that are more vulnerable to being affected. The government is also expected to
establish a strong and independent data monitoring institution to defend the personal data
and privacy rights of United States citizens.
United States has Law No. 11/2008 on Electronic Information and Transactions (ITE
Law) which also covers aspects of personal data protection. However, according to the
author, this law is not strong enough to protect personal data. In November 2020, United
States passed the Personal Data Protection Bill (RUU PDP) to enhance this protection. The
bill adopts the general principles found in the European Union's General Data Protection
Regulation (GDPR). The European Union is represented by the General Data Protection
Regulation (GDPR), which came into force in May 2018. The GDPR provides a robust
framework for protecting the personal data of EU citizens and regulates how data can be
collected, processed and stored. The GDPR gives individuals the right to control their
personal data and imposes significant sanctions on companies that violate these regulations.
Personal data protection is also practiced in the United States, which has a different
approach to personal data protection. In the US, there is no comprehensive federal law
governing personal data protection in general. Instead, various sectoral and state laws may
393
apply. The California Consumer Privacy Act (CCPA) is one example of a significant state
law, giving California residents the right to control companies' use of their personal data. In
general, the European Union has one of the most robust personal data protection frameworks
through the GDPR, with an emphasis on individual rights and strict sanctions. United States
is looking to improve its personal data protection through the PDP Bill, while the US tends
to have a more fragmented approach.
Conclusion
Several implied articles protecting personal data continue to apply in United States as
a form of legal protection of personal data as a right to privacy. United States does not yet
have specific laws and regulations governing the protection of personal data, but it already
has a Personal Data Protection Bill as a means of implementing the government's duty to
protect the constitutional rights of United States citizens as stipulated in the law in the 1945
Constitution, particularly in Article 28 letter G paragraph (1). The PDP Law has
shortcomings, including the way the privacy of data on children and persons with disabilities
is specifically regulated. However, there is a tendency for all information about children and
persons with disabilities to be misused. The 'special' process mentioned in the PDP Law is
not precisely regulated, and there is no age limit for children to be classified, among other
shortcomings. It is hoped that the PDP Law will provide stronger protection for children's
data and data belonging to more vulnerable groups, and that the government will be able to
establish a strong and independent data monitoring authority to protect the privacy rights of
United Statess.