Seri Ekonomi Digital: Pentingnya Perlindungan Data Pribadi di Indonesia

CIPS Learning Hub
21 Mar 202105:16

Summary

TLDRThe video script discusses the importance of personal data privacy and the need for companies and governments to respect and protect it. It highlights the increase in digital services requiring personal data processing and storage, yet often overlooking privacy. The script mentions the lack of specific regulations in Indonesia, referencing a data breach involving 15 million Tokopedia users in May 2021. It also talks about the ongoing deliberation of the Personal Data Protection bill (RUU PDP) aimed at empowering data owners with full control over their information. The video calls for transparency, limits on government access to personal data, and the establishment of an independent body to oversee the implementation of privacy regulations. It suggests the adoption of a regulatory sandbox to test policies before full implementation, emphasizing the need for a diverse perspective in policy-making.

Takeaways

  • 📞 People often receive unsolicited calls for offers of goods or services, despite not giving their phone numbers to these parties, indicating a potential breach of personal data privacy.
  • 🔒 Personal data is a right belonging to individuals, and they have the authority to control its confidentiality. Companies and governments should respect this by obtaining consent before using personal data.
  • 🚫 Unauthorized use of personal data without permission should be met with sanctions to deter such actions.
  • 📈 In the digital era, there's an increase in digital services that require companies to process and store personal data, yet privacy is often overlooked.
  • 🗓️ The lack of specific regulations for data privacy in Indonesia was highlighted by the May 2021 data leak of 15 million Tokopedia users, where the perpetrator claimed to have 91 million user data and sold it on the dark web.
  • 📋 The absence of regulations for compensation for affected consumers or sanctions for companies whose data has been breached is a significant issue.
  • 🛠️ The Indonesian House of Representatives is currently discussing the Personal Data Protection Bill (RUU PDP), aimed at giving data owners full control over their personal data.
  • 🏢 The RUU PDP proposes that companies or the state must respect data owners' rights, with exceptions for national defense and security, law enforcement, financial oversight, and financial system stability.
  • 🚷 The RUU PDP allows the government unlimited access to personal data without specific definitions and limits, requiring transparency for the exceptions and data storage period.
  • 👥 The establishment of an independent body to oversee the implementation of the RUU PDP is not yet clear, with current oversight powers given to the Ministry of Communication and Informatics.
  • 🚨 The sanctions mentioned in the RUU PDP are categorized as administrative and criminal, indicating a need for systematic and extensive activities to profile individuals and monitor accessible public areas.
  • 🤝 The script encourages the government to involve the private sector and the public in the creation and discussion of the RUU to gain diverse perspectives.
  • 🔍 Companies planning activities involving personal data should consult with supervisory authorities in Indonesia and conduct detailed privacy impact assessments, informing potentially affected individuals of the risks.

Q & A

  • What is the main concern discussed in the script regarding personal data privacy?

    -The main concern is the misuse and lack of proper protection of personal data privacy, especially in the digital era where companies and governments should respect and obtain consent before using personal data.

  • What are the consequences of personal data being misused without permission?

    -The misuse of personal data without permission can lead to unsolicited calls from unknown parties offering products or services, and it can also result in data breaches, compromising the privacy and security of individuals.

  • What incident mentioned in the script highlights the issue of data privacy in Indonesia?

    -The incident of data leakage involving 15 million Tokopedia users in May 2021, where the hacker claimed to have 91 million user data and sold it on the dark web, highlights the issue of data privacy in Indonesia.

  • What is the role of the government in protecting personal data privacy according to the script?

    -The government should respect the rights of data owners, obtain consent before using personal data, and impose sanctions on parties that misuse data without permission.

  • What is the significance of the Personal Data Protection Bill (RUU PDP) being discussed in the script?

    -The RUU PDP aims to provide data owners with full control over their personal data, ensuring that companies and the state respect these rights and that there are legal consequences for misuse.

  • What are the exceptions mentioned in the script where personal data can be used without consent?

    -Exceptions include situations necessary for national defense and security, law enforcement, financial system supervision, or financial stability.

  • What is the concern regarding the RUU PDP's handling of sanctions for data misuse?

    -The concern is that the sanctions mentioned in the RUU PDP are categorized as administrative and criminal, which may not be sufficient to deter misuse or provide adequate compensation for affected data owners.

  • What is the role of an independent body in overseeing the implementation of the RUU PDP as discussed in the script?

    -An independent body is suggested to monitor the implementation of the RUU PDP, ensuring transparency, accountability, and proper handling of personal data privacy issues.

  • What is the concept of a 'regulatory sandbox' as mentioned in the script?

    -A regulatory sandbox is a testing mechanism used by financial authorities to evaluate the reliability of business processes, financial instruments, and management before granting legal licenses.

  • How can the government ensure a diverse perspective in the creation and discussion of the RUU PDP?

    -The government can involve the private sector and the public in the creation and discussion of the RUU PDP to gain a broader range of perspectives and insights.

  • What is the advice given to companies planning to be involved in activities related to personal data privacy?

    -Companies should consult with supervisory authorities in Indonesia before engaging in activities related to personal data privacy, conduct a detailed privacy impact assessment, and inform individuals who may be affected by potential data breaches.

Outlines

00:00

🔒 Data Privacy Concerns and the Need for Legislation

The first paragraph discusses the importance of personal data privacy and the issues arising from its misuse. It highlights the common scenario where individuals receive unsolicited calls after providing personal information online, suggesting a breach of privacy. The paragraph points out the lack of strict regulations in Indonesia to protect personal data, referencing the May 2021 data leak of 15 million Tokopedia users. It also mentions the ongoing deliberation of the Personal Data Protection Bill (RUU PDP) by the House of Representatives, which aims to empower data owners with full control over their information. The RUU PDP is criticized for not clearly defining the establishment of an independent body to oversee its implementation and for its vague sanctions, which are categorized as administrative and criminal. The paragraph concludes with a call for the government to involve the private sector and public in the legislation process to gain diverse perspectives and to consider adopting a regulatory sandbox approach to test policies before full implementation.

05:00

⚠️ Caution Against Downloading Fake Apps

The second paragraph serves as a warning to the audience to be vigilant about the information they access and download. It advises the audience to download the authentic 'Bridge' app through the provided link in the description to avoid counterfeit versions. This brief paragraph emphasizes the importance of ensuring the security and authenticity of the apps being used, likely in the context of data privacy discussed in the previous paragraph.

Mindmap

Keywords

💡Data Privacy

Data privacy refers to the right of individuals to have control over their personal information and to limit the collection, use, and distribution of that information. In the video's context, it is highlighted as a fundamental right that should be respected by companies and governments. The script mentions that personal data, such as phone numbers and ID photos, should not be misused or shared without consent, as seen in the case of the data breach involving 15 million Tokopedia users.

💡Social Media Accounts

Social media accounts are digital profiles created on various online platforms for communication and interaction. The script raises a concern about the privacy implications of entering personal phone numbers when creating these accounts, which can lead to unsolicited calls and offers, indicating a potential misuse of personal data.

💡Financial Applications

Financial applications, or fintech apps, are software designed to manage financial transactions and services. The script discusses the practice of uploading ID photos for account verification in these apps, which raises concerns about data privacy and the potential for data leaks, as personal identification information is highly sensitive.

💡Data Breach

A data breach occurs when unauthorized individuals gain access to confidential or sensitive information. The script cites the example of a data leak involving 15 million Tokopedia users, where the hackers claimed to have 91 million user data and sold it on the dark web, illustrating the severity and real-world consequences of data breaches.

💡Dark Web

The dark web is a part of the internet that is not indexed by traditional search engines and requires specific software to access. It is often associated with illegal activities, such as the sale of stolen data, as mentioned in the script where the stolen data from Tokopedia was sold for a significant amount of money.

💡Regulation

Regulation refers to the rules and policies set by governing bodies to control behavior and ensure compliance with laws. The script discusses the need for regulations like the Personal Data Protection Bill (RUU PDP) to protect data privacy and give individuals control over their personal information.

💡RUU PDP

RUU PDP, or the Personal Data Protection Bill, is a legislative draft in Indonesia aimed at providing full rights to data owners to control and manage their personal data. The script explains that this bill is crucial for ensuring that companies and the government respect data privacy rights and obtain consent before using personal data.

💡Data Sovereignty

Data sovereignty is the concept of having authority and control over one's data. The script mentions that the RUU PDP intends to strengthen data sovereignty by compelling entities to respect the rights of data owners and obtain permission before processing or storing personal data.

💡Regulatory Sandbox

A regulatory sandbox is a framework set up by regulatory authorities to test new products or services in a controlled environment before they are launched to the public. The script suggests that the Indonesian government could use a regulatory sandbox to evaluate the effectiveness of the RUU PDP and ensure it is neither too strict nor too lenient.

💡Data Processing

Data processing involves the collection, manipulation, storage, and retrieval of data. The script highlights the need for companies to obtain, process, and store personal data for digital services, but emphasizes that this should be done with respect for data privacy and the consent of the data owner.

💡Data Consent

Data consent is the voluntary and explicit agreement given by an individual to the collection and use of their personal data. The script stresses the importance of obtaining data consent from the data owner before its use, as a fundamental aspect of respecting data privacy rights.

Highlights

Individuals should be cautious about sharing personal information like phone numbers and ID photos on social media and financial apps.

Unauthorized use of personal data by unknown parties can lead to unsolicited calls for marketing purposes.

Personal data privacy is a right that should be respected by companies and governments, requiring consent before its use.

In the digital era, there is an increase in digital services that necessitate the collection, processing, and storage of personal data.

Data privacy is often overlooked, and there is a lack of specific regulations to protect it in Indonesia.

In May 2021, a data breach at Tokopedia exposed the information of 15 million users, highlighting the need for better data protection.

Hackers claimed to have 91 million user data and sold it on the dark web for $5000 or 75 million rupiah.

There is no regulation in place to compensate consumers affected by data breaches or to impose sanctions on companies whose data is hacked.

The Indonesian House of Representatives is currently discussing the Personal Data Protection Bill (RUU PDP), initiated by the Ministry of Communication and Information Technology.

The RUU PDP aims to give data owners full control over their personal data, requiring companies and the state to respect this right.

The bill suspends the right to choose data in cases where data is needed for national defense, law enforcement, financial sector supervision, or financial system stability.

The government should have limited access to personal data, with transparency required for the purpose and duration of data storage.

The RUU PDP does not yet clarify the establishment of an independent body to oversee the implementation of the bill.

The sanctions mentioned in the RUU PDP fall under administrative and criminal categories.

High-risk areas involving systematic and extensive activities to create individual profiles require special attention.

Entities planning to engage in such activities must consult with supervisory authorities in Indonesia before proceeding.

A thorough privacy impact assessment and notification of potentially affected individuals are necessary in case of data breaches.

The Indonesian government is encouraged to involve the private sector and the public in the creation and discussion of the RUU to gain diverse perspectives.

The government can adopt the use of regulatory sandboxes to test policies before full implementation, as seen in Singapore and the People's Republic of China.

The regulatory sandbox, according to the Financial Services Authority (OJK), is a mechanism for testing the reliability of business processes, models, and financial instruments.

The OJK allows a few prototypes that are registered and selected to operate for one year before being granted legal status.

In the context of data protection, the Indonesian government can try implementing ERP in related companies and evaluate whether the applied law is too strict or too loose.

Users should be cautious about the applications they download and the data they provide, as it can impact their privacy.

Transcripts

play00:00

Hai perlindungan data pribadi Pernahkah

play00:03

kamu memasukkan nomor ponsel ketika

play00:05

membuat akun media sosial atau Pernahkah

play00:07

kamu mengunggah foto KTP ketika kamu

play00:10

membuat akun di aplikasi keuangan

play00:12

setelahnya Pernahkah kamu mendapatkan

play00:15

telepon dari pihak yang tidak dikenal

play00:16

untuk menawarkan barang atau jasa

play00:18

padahal kamu tidak pernah merasa

play00:20

memberikan nomor HP kamu ke mereka data

play00:23

pribadi adalah hak milikmu dan kamu juga

play00:25

berhak mengatur kerahasiaannya

play00:27

perusahaan dan pemerintah seharusnya

play00:30

menghormati hakmu tersebut yang artinya

play00:32

mereka harus mendapatkan izin dari

play00:35

pemilik data jika mereka ingin

play00:36

menggunakannya jika ada tamu digunakan

play00:39

tanpa izin darimu pihak tersebut

play00:41

seharusnya dapat dikenakan sanksi pada

play00:44

era digital saat ini terdapat

play00:46

peningkatan layanan digital yang

play00:48

mengharuskan perusahaan memperoleh

play00:50

memproses dan menyimpan data pribadi

play00:53

sayangnya kerahasiaan data pribadi

play00:56

seringkali tidak diperhatikan dan tidak

play00:58

ada peraturan khusus yang

play01:00

lebih hak memilih data pribadi di

play01:02

Indonesia seperti misalnya kejadian pada

play01:04

Mei 2021 hii di kebocoran data milik 15

play01:08

juta pengguna Tokopedia peretas yang

play01:10

membocorkan data tersebut lanjut

play01:12

mengklaim Ia memiliki 91 juta data

play01:15

pengguna dan menjualnya ke darkwebs

play01:17

nilai 5000s Dollar atau 75 juta rupiah

play01:21

ironisnya belum ada regulasi yang

play01:23

mengatur ganti rugi yang didapatkan oleh

play01:25

konsumen Tokopedia selaku pemilik data

play01:28

yang dirugikan atau yang menetapkan

play01:30

sanksi terhadap Tokopedia sebagai

play01:31

pemberi layanan yang datanya diretas

play01:33

dalam upaya memperbaiki situasi seperti

play01:36

dalam contoh masalah diatas DPR saat ini

play01:39

tengah membahas rancangan undang-undang

play01:41

perlindungan data pribadi atau RUU PDP

play01:44

yang diprakarsai oleh Kementerian

play01:46

komunikasi dan Informatika RUU PDP

play01:49

tersebut bertujuan untuk memberikan

play01:50

pemilik data hak penuh untuk

play01:52

mengendalikan dan mengelola data pribadi

play01:54

mereka sehingga ada dorongan kuat bagi

play01:58

perusahaan atau negara agar

play02:00

bingung jawab untuk menghormati hak

play02:01

tersebut RUU tersebut menangguhkan hak

play02:04

memilih data dalam hal datanya

play02:06

diperlukan untuk pertahanan dan keamanan

play02:08

negara penegakan hukum penyelenggaraan

play02:12

negara pengawasan sektor keuangan atau

play02:14

moneter sistem pembayaran atau

play02:17

stabilitas sistem keuangan pengecualian

play02:20

ini memberi pemerintah akses yang tidak

play02:22

terbatas ke data pribadi harus ada

play02:24

definisi khusus dan batasan untuk akses

play02:27

pemerintah yang mewajibkan transparansi

play02:29

untuk tujuan pengecualian dan periode

play02:31

penyimpanan data Selain itu RUU PDP juga

play02:35

belum menjelaskan tentang pendirian

play02:37

badan independen untuk mengawasi

play02:39

implementasi dari RUU tersebut wewenang

play02:41

tersebut masih diberikan kepada

play02:43

kemenkominfo yang notabene merupakan

play02:45

lembaga pemerintah hal lain yang juga

play02:47

perlu diperhatikan adalah bahwa sanksi

play02:50

yang disebutkan dalam RUU PDP masuk

play02:53

dalam kategori administratif dan

play02:55

kriminal Oleh karena itu RUU PDP harus

play02:58

mengikuti pendekatan berbasis

play03:00

risiko area beresiko tinggi haruslah

play03:03

yang melibatkan aktivitas sistematis dan

play03:05

ekstensif untuk membuat profil individu

play03:07

untuk memproses kategori data khusus dan

play03:10

untuk memantau area yang dapat diakses

play03:12

publik mereka yang Berencana untuk

play03:14

terlibat dalam kegiatan ini harus

play03:16

berkonsultasi dengan otoritas pengawas

play03:19

di Indonesia sebelum melakukan kegiatan

play03:21

tersebut mereka perlu melakukan

play03:23

penilaian dampak privasi terperinci dan

play03:26

memberitahu individu yang berpotensi

play03:28

terkena dampak jika terjadi pelanggaran

play03:30

data Centre for Indonesian palsy stadis

play03:33

mendorong pemerintah untuk selalu

play03:35

melibatkan sektor swasta serta

play03:37

masyarakat dalam pembuatan dan

play03:39

pembahasan RUU ini sehingga pemerintah

play03:41

bisa mendapatkan perspektif yang lebih

play03:43

beragam Selain itu seperti yang sudah

play03:46

dilakukan di Singapura dan Republik

play03:48

Rakyat Tiongkok atau rrt pemerintah juga

play03:51

bisa mengadopsi penggunaan regulatory

play03:53

sandbox untuk menguji coba Kebijakan

play03:55

sebelum benar-benar diterapkan Apa itu

play03:58

regulatory sandbox

play04:00

the regulatory sandbox menurut surat

play04:02

edaran Otoritas Jasa Keuangan atau OJK

play04:05

adalah mekanisme pengujian yang

play04:07

dilakukan oleh Otoritas Jasa Keuangan

play04:09

untuk menilai keandalan proses bisnis

play04:12

model bisnis instrumen keuangan dan tata

play04:16

kelola jadi OJK memberikan waktu ke

play04:19

beberapa prototipe yang daftar dan

play04:21

terpilih untuk beroperasi satu tahun

play04:24

sebelum dia bisa diberikan cap legal

play04:26

sebelumnya dalam masa uji coba Prototype

play04:29

tersebut hanya mendapatkan cap terdaftar

play04:32

saja dalam konteks perlindungan data

play04:34

pribadi pemerintah Indonesia dapat

play04:36

mencoba menerapkan erp ke beberapa

play04:39

perusahaan terkait lalu menilai Apakah

play04:42

RUU yang diterapkan terlalu ketat atau

play04:44

terlalu longgar sehingga dapat dijadikan

play04:47

evaluasi sebagai pemilik rumah kita

play04:51

harus memperhatikan Siapa tamu yang

play04:53

mampir ke rumah kita dan mengontrol apa

play04:55

yang ia minta begitu pula dengan gadget

play04:58

kita aplikasi apa

play05:00

dan kamu unduh data apa yang diminta

play05:02

aplikasi itu teruslah berhati-hati untuk

play05:05

informasi yang lebih lengkap dauwnload

play05:08

palsu Bridge kami melalui Link yang ada

play05:10

pada kolom deskripsi

play05:14

yo yo

Rate This

5.0 / 5 (0 votes)

Related Tags
Data PrivacyDigital RegulationsIndonesiaSocial MediaFinancial AppsData BreachConsumer RightsRegulatory SandboxCybersecurityData Protection