The Regulations of the Supervisory Officer Personal Data Protection-Based Accountability Principle
This study examines The Model of Regulations Supervisory Officer Personal Data Protection-Based Accountability Principle: Lessons from Sweden. This study is a qualitative approach by reviewing and analyzing legal aspects and comparing laws. Even though Indonesia has a personal data protection law, misuse of personal data is still excessive. Owing to accountability basis PDP supervision arrangements have not been properly implemented. Meanwhile, Sweden was chosen as a comparison country since it was one of the first countries to have a personal data protection law. The result shows that in Sweden, personal data is regulated in the General Data Protection Regulation and the personal data supervisor well implemented the principle of accountability therefore it worked effectively. Meanwhile in Indonesia, given that a data protection supervisor has not been established, Protection of personal data is still carried out by each agency appointed by law on a sectoral basis and it deemed less effective in providing personal data protection. Therefore, the personal data supervisor with a single rule and direct responsibility to the president is the perfect model for Indonesia.
Full Text:
Adhiwisaksana, Muhammad Faqih, and Tiurma M.Pitta Allagan, ‘The Competent Forum and the Applicable Law in Personal Data Protection With Foreign Element’, Indonesian Journal of International Law, 20.3 (2023), 442–70
Aldhouse, Francis, ‘A Reflection on the Priorities of a Data Protection Authority’, Computer Law and Security Review, 34.4 (2018), 816–23
Algamar, Muhammad Deckri, and Noriswadi Ismail, ‘Data Subject Access Request: What Indonesia Can Learn and Operationalise in 2024?’, Journal of Central Banking Law and Institutions, 2.3 (2023), 481–512
Alibeigi, Ali, Abu Bakar Munir, and Adeleh Asemi, ‘Compliance with Malaysian Personal Data Protection Act 2010 by Banking and Financial Institutions, a Legal Survey on Privacy Policies’, International Review of Law, Computers and Technology, 35.3 (2021), 365–94
Andhikaputra, Raditya, Samuel Marc Anthony Tumbel, Jason Vida, Anderes Gui, I Gusti Made Karmawan, and Yuvaraj Ganesan, ‘User’s Awareness of Personal Data Leakage in E-Commerce Application’, in E3S Web of Conferences, 2023, cdxxvi
Bayamlıoğlu, Emre, ‘The Right to Contest Automated Decisions under the General Data Protection Regulation: Beyond the so-Called “Right to Explanation”’, Regulation and Governance, 16.4 (2022), 1058–78
Bekkum, Marvin van, and Frederik Zuiderveen Borgesius, ‘Using Sensitive Data to Prevent Discrimination by Artificial Intelligence: Does the GDPR Need a New Exception?’, Computer Law and Security Review, 48 (2023), 105770
Belen Saglam, Rahime, Jason R.C. Nurse, and Duncan Hodges, ‘Personal Information: Perceptions, Types and Evolution’, Journal of Information Security and Applications, 66.March (2022), 103163
Bentotahewa, Vibhushinie, Chaminda Hewage, and Jason Williams, ‘The Normative Power of the GDPR: A Case Study of Data Protection Laws of South Asian Countries’, SN Computer Science, 3.3 (2022), 1–18
Borgesius, Frederik Zuiderveen, Hadi Asghari, Noël Bangma, and Jaap-Henk Hoepman, ‘The GDPR’s Rules on Data Breaches: Analysing Their Rationales and Effects’, SCRIPTed: A Journal of Law, Technology & Society, 20.2 (2023), 352–82
Breen, Stephen, Karim Ouazzane, and Preeti Patel, ‘GDPR: Is Your Consent Valid?’, Business Information Review, 37.1 (2020), 19–24
Bu-Pasha, Shakila, ‘Cross-Border Issues under EU Data Protection Law with Regards to Personal Data Protection’, Information and Communications Technology Law, 26.3 (2017), 213–28
Cantiello, Pasquale, Michele Mastroianni, and Massimiliano Rak, ‘A Conceptual Model for the General Data Protection Regulation’, in Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2021, 12956 LNCS, 60–77
Chatsuwan, Panchapawn, Tanawat Phromma, Navaporn Surasvadi, and Suttipong Thajchayapong, ‘Personal Data Protection Compliance Assessment: A Privacy Policy Scoring Approach and Empirical Evidence from Thailand’s SMEs’, Heliyon, 9.10 (2023), e20648
Cochrane, Leanne, Lina Jasmontaite-Zaniewicz, and David Barnard-Wills, ‘Data Protection Authorities and Their Awareness-Raising Duties under the GDPR: The Case for Engaging Umbrella Organisations to Disseminate Guidance for Small and Medium-Size Enterprises’, European Data Protection Law Review, 6.3 (2020), 352–64
Crutzen, Rik, Gjalt Jorn Ygram Peters, and Christopher Mondschein, ‘Why and How We Should Care about the General Data Protection Regulation’, Psychology and Health, 34.11 (2019), 1347–57
Cruz, Tiago, Luis Rosa, Jorge Proenca, Leandros Maglaras, Matthieu Aubigny, Leonid Lev, and others, ‘A Cybersecurity Detection Framework for Supervisory Control and Data Acquisition Systems’, IEEE Transactions on Industrial Informatics, 12.6 (2016), 2236–46
Custers, Bart, Francien Dechesne, Alan M. Sears, Tommaso Tani, and Simone van der Hof, ‘A Comparison of Data Protection Legislation and Policies across the EU’, Computer Law and Security Review, 34.2 (2018), 234–43
Dahi, Alan, and Marcelo Corrales Compagnucci, ‘Device Manufacturers as Controllers – Expanding the Concept of “Controllership” in the GDPR’, Computer Law & Security Review, 47 (2022)
Dudás, Gábor János, András György Kovács, and Márton Schultz, ‘Personal Data as Consideration’, Santander Art and Culture Law Review, 9.2 (2023), 215–42
Garrison, Chlotia, and Clovia Hamilton, ‘A Comparative Analysis of the EU GDPR to the US’s Breach Notifications’, Information and Communications Technology Law, 28.1 (2019), 99–114
Greenleaf, Graham, ‘ASEAN’s “New” Data Privacy Laws: Malaysia, the Philippines and Singapore’, Privacy Laws & Business International Report, UNSW Law R.116 (2012), 22–24
Gregory Voss, W., and Kimberly A. Houser, ‘Personal Data and the Gdpr: Providing a Competitive Advantage for u.s. Companies’, American Business Law Journal, 56.2 (2019), 287–344
Hajduk, Paweł, ‘The Powers of the Supervisory Body in the GDPR as a Basis for Shaping the Practices of Personal Data Processing’, Review of European and Comparative Law, 45.2 (2021), 57–75
Hallinan, Dara, ‘Broad Consent under the GDPR: An Optimistic Perspective on a Bright Future’, Life Sciences, Society and Policy, 16.1 (2020), 1–18
Haq, Md Zahurul, ‘How Does the General Data Protection Regulation (GDPR) Affect Financial Intelligence Exchange with Third Countries?’, Journal of Money Laundering Control, 27.1 (2024), 158–70
Hendra, Hendra, Ravel Ravel, Novel Firdhaus, Michael Ari Kurniawan, and Gilbert Platina, ‘E-Health Personal Data Protection In Indonesia’, Jurnal Hukum Kesehatan Indonesia, 1.02 (2022), 121–31
Herlin-Karnell, Ester, ‘EU Data Protection Rules and the Lack of Compliance in Sweden’, Nordic Journal of European Law, 3.2 (2020), 95–103
Hicks, Deborah, ‘Information Technology, Change and Information Professionals’ Identity Construction: A Discourse Analysis’, Proceedings of the ASIST Annual Meeting, 51.1 (2014)
Hoofnagle, Chris Jay, Bart van der Sloot, and Frederik Zuiderveen Borgesius, ‘The European Union General Data Protection Regulation: What It Is and What It Means’, Information and Communications Technology Law, 28.1 (2019), 65–98
Issaoui, Awatef, Jenny Örtensjö, and M Sirajul Islam, ‘Exploring the General Data Protection Regulation (GDPR) Compliance in Cloud Services: Insights from Swedish Public Organizations on Privacy Compliance’, Future Business Journal, 9.1 (2023)
Knezevic, Zlatana, Anna Nikupeteri, Merja Laitinen, and Kati Kallinen, ‘Gender-and Power Sensitivity, Securitisation and Social Peace: Rethinking Protection for Children Exposed to Post-Separation Violence’, Journal of Gender-Based Violence, 6.1 (2022), 99–114
Kolasa, Katarzyna, W. Ken Redekop, Alexander Berler, Vladimir Zah, and Carl V. Asche, ‘Future of Data Analytics in the Era of the General Data Protection Regulation in Europe’, PharmacoEconomics, 38.10 (2020), 1021–29
Kopcha, Vasyl, ‘Methodology of Legal Phenomenon Research: Concept, Structure, Tools’, Law Review of Kyiv University of Law, 1, 2020, 54–58
Kulesza, Ewa, ‘The Protection of Customer Personal Data as an Element of Entrepreneurs’ Ethical Conduct’, Annales. Etyka w Życiu Gospodarczym, 21.7 (2018), 27–44
Lachaud, Eric, ‘What GDPR Tells about Certification’, Computer Law and Security Review, 38 (2020), 105457
Lestari, Yuliannova, and M. Misbahul Mujib, ‘Optimizing Personal Data Protection Legal Framework in Indonesia (a Comparative Law Study)’, Supremasi Hukum: Jurnal Kajian Ilmu Hukum, 11.2 (2022), 203
Lorè, Filippo, Pierpaolo Basile, Annalisa Appice, Marco de Gemmis, Donato Malerba, and Giovanni Semeraro, ‘An AI Framework to Support Decisions on GDPR Compliance’, Journal of Intelligent Information Systems, 61.2 (2023), 541–68
Malatras, Apostolos, Ignacio Sanchez, Laurent Beslay, Iwen Coisel, Ioannis Vakalis, Giuseppe D’Acquisto, and others, ‘Pan-European Personal Data Breaches: Mapping of Current Practices and Recommendations to Facilitate Cooperation among Data Protection Authorities’, Computer Law & Security Review, 33.4 (2017), 458–69
Mantelero, Alessandro, ‘The Future of Data Protection: Gold Standard vs. Global Standard’, Computer Law and Security Review, 40.xxxx (2021), 1–5
Maras, Marie Helen, and Alex Alexandrou, ‘Determining Authenticity of Video Evidence in the Age of Artificial Intelligence and in the Wake of Deepfake Videos’, International Journal of Evidence and Proof, 23.3 (2019), 255–62
Meurisch, Christian, and Max Mühlhäuser, ‘Data Protection in AI Services’, ACM Computing Surveys, 2021, 1–38
Mutiro, Blessing, ‘The Future of EU Data Protection Law for Collectives: A Reverse Brussels Effect’, European Data Protection Law Review, 9.4 (2023), 409–17
Natarajan Ramani, Gaurav, ‘One Size Doesn’t Fit All: The General Data Protection Regulation Vis-à-Vis International Commercial Arbitration’, Arbitration International, 37.3 (2021), 613–30
Neta, Yulia, Agsel Awanisa, and Melisa Melisa, ‘The Urgency of Independent Supervisory Authority Towards Indonesia’s Personal Data Protection’, Constitutionale, 3.1 (2022), 21–42
Nugroho, Andriyanto Adhi, Atik Winanti, and Surahmad Surahmad, ‘Personal Data Protection in Indonesia: Legal Perspective’, International Journal of Multicultural and Multireligious Understanding, 7.7 (2020), 183
Padden, Michaela, and Andreas Öjehag-Pettersson, ‘Protected How? Problem Representations of Risk in the General Data Protection Regulation (GDPR)’, Critical Policy Studies, 15.4 (2021), 486–503
Partogi Sihombing, Januardo Sulung, Retno Saraswati, Yunanto Yunanto, and Arida Turymshayeva, ‘The Regulation of Legal Protection for Poor Communities Toward Justice in Indonesia and the Netherlands’, Journal of Human Rights, Culture and Legal System, 4.2 (2024), 331–53
Perez, Nahshon, ‘Posner’s “Law and Economics” and Politics: Bringing State-Skepticism Back In’, Journal of Social Philosophy, 49.4 (2018), 589–609
Phillips, Mark, ‘International Data-Sharing Norms: From the OECD to the General Data Protection Regulation (GDPR)’, Human Genetics, 137.8 (2018), 575–82
Pikulík, Tomáš, and Peter Štarchoň, ‘Public Registers with Personal Data under Scrutiny of DPA Regulators’, Procedia Computer Science, 170.2019 (2020), 1170–79
Posner, Richard A, ‘Law and Economics in Common-Law, Civil-Law, and Developing Nations’, Ratio Juris, 17.1 (2004), 66–79
Prabowo, Sidik, Maman Abdurohman, Hilal Hudan Nuha, and Sarwono Sutikno, ‘A Data Protection Design for Online Exam Proctoring in Compliance with the Indonesian Personal Data Protection Law’, in Lecture Notes in Networks and Systems (Springer Science and Business Media Deutschland GmbH, 2024), 824 LNNS, 523–35
Prastyanti, Rina Arum, and Ridhima Sharma, ‘Establishing Consumer Trust Through Data Protection Law as a Competitive Advantage in Indonesia and India’, Journal of Human Rights, Culture and Legal System, 4.2 (2024), 354–90
Puljak, Livia, Anamarija Mladinić, and Zvonimir Koporc, ‘Workload and Procedures Used by European Data Protection Authorities Related to Personal Data Protection: A Cross-Sectional Study’, BMC Research Notes, 16.1 (2023), 1–7
Purtova, Nadezhda, ‘The Law of Everything. Broad Concept of Personal Data and Future of EU Data Protection Law’, Law, Innovation and Technology, 10.1 (2018), 40–81
Quelle, Claudia, ‘Enhancing Compliance under the General Data Protection Regulation: The Risky Upshot of the Accountability- and Risk-Based Approach’, European Journal of Risk Regulation, 9.3 (2018), 502–26
Raab, Charles, and Ivan Szekely, ‘Data Protection Authorities and Information Technology’, Computer Law and Security Review, 33.4 (2017), 421–33
Reksoprodjo, Aqil Athalla, Muhammad Dachyar, and Novandra Rhezza Pratama, ‘A Decision-Making Model for Selecting Personal Data Protection Frameworks for Companies in Indonesia’, Journal of System and Management Sciences, 14.2 (2024), 156–71
Rubinstein, Ira S., and Nathaniel Good, ‘The Trouble with Article 25 (and How to Fix It): The Future of Data Protection by Design and Default’, International Data Privacy Law, 10.1 (2020), 37–56
Rukmono, Bambang Sugeng, Pujiyono Suwadi, and Muhammad Saiful Islam, ‘The Effectiveness of Recovering Losses on State Assets Policy in Dismissing Handling of Corruption’, Journal of Human Rights, Culture and Legal System, 4.2 (2024), 299–330
Ruohonen, Jukka, and Kalle Hjerppe, ‘The GDPR Enforcement Fines at Glance’, Information Systems, 106 (2022), 101876
Rupp, Valentin, and Max von Grafenstein, ‘Clarifying “Personal Data” and the Role of Anonymisation in Data Protection Law Including and Excluding Data from the Scope of the GDPR (More Clearly) through Refining the Concept of Data Protection’, Computer Law and Security Review, 52.1 (2024), 105932
Safira Widya Attidhira, and Yana Sukma Permana, ‘Review Of Personal Data Protection Legal Regulations In Indonesia’, Awang Long Law Review, 5.1 (2022), 280–94
Setiawan, Heru, I Gusti Ayu Ketut Rachmi Handayani, M. Guntur Hamzah, and Hilaire Tegnan, ‘Digitalization of Legal Transformation on Judicial Review in the Constitutional Court’, Journal of Human Rights, Culture and Legal System, 4.2 (2024), 263–98
Shahrullah, Rina Shahriyani, Jihyun Park, and Irwansyah Irwansyah, ‘Examining Personal Data Protection Law of Indonesia and South Korea: The Privacy Rights Fulfilment’, Hasanuddin Law Review, 10.1 (2024), 1–20
Sholikhah, Vina Himmatus, Noering Ratu Fatheha Fauziah Sejati, and Diyanah Shabitah, ‘Personal Data Protection Authority: Comparative Study between Indonesia, United Kingdom, and Malaysia’, Indonesian Scholars Scientific Summit Taiwan Proceeding, 3 (2021), 54–63
Simani, Silvio, Saverio Farsoni, and Paolo Castaldi, ‘Supervisory Control and Data Acquisition for Fault Diagnosis of Wind Turbines via Deep Transfer Learning’, Energies, 16.9 (2023), 3644
Sørum, Hanne, Ragnhild Eg, and Wanda Presthus, ‘A Gender Perspective on GDPR and Information Privacy’, Procedia Computer Science, 196.2021 (2021), 175–82
Stepenko, Valery, Lyudmila Dreval, Sergei Chernov, and Viktor Shestak, ‘EU Personal Data Protection Standards and Regulatory Framework’, Journal of Applied Security Research, 17.2 (2022), 190–207
Sudarwanto, Al Sentot, and Dona Budi Budi Kharisma, ‘Comparative Study of Personal Data Protection Regulations in Indonesia, Hong Kong and Malaysia’, Journal of Financial Crime, 29.4 (2022), 1443–57
Supriyadi, Daniar, ‘The Regulation of Personal and Non-Personal Data in the Context of Big Data’, Journal of Human Rights, Culture and Legal System, 3.1 (2023), 33–69
Truong, Nguyen Binh, Kai Sun, Gyu Myoung Lee, and Yike Guo, ‘GDPR-Compliant Personal Data Management: A Blockchain-Based Solution’, IEEE Transactions on Information Forensics and Security, 15 (2020), 1746–61
Tsekoura, Talita Maria, and Fereniki Panagopoulou, ‘GDPR: A Critical Review of the Practical, Ethical and Constitutional Aspects One Year after It Entered into Force’, International Journal of Human Rights and Constitutional Studies, 7.1 (2020), 35
Uddin, Mohammad Rajib, Shahriar Akter, and Wai Jin Thomas Lee, ‘Developing a Data Breach Protection Capability Framework in Retailing’, International Journal of Production Economics, 271.October 2023 (2024), 109202
Vanberg, Aysem Diker, ‘Informational Privacy Post GDPR–End of the Road or the Start of a Long Journey?’, International Journal of Human Rights, 0.0 (2020), 52–78
Vigna, Francesco, ‘Co-Regulation Approach for Governing Big Data: Thoughts on Data Protection Law’, in ACM International Conference Proceeding Series, 2022, pp. 59–63
Wagner, Julian, ‘The Transfer of Personal Data to Third Countries under the GDPR: When Does a Recipient Country Provide an Adequate Level of Protection?’, International Data Privacy Law, 8.4 (2018), 318–37
Wardiono, Kelik, and Wardah Yuspin, ‘The Sharia Microfinance and the Counter-Hegemonic Movement: Examining the Legal Norms Regulating Aspects of Institutional and Business Activities in Surakarta’, Humanities and Social Sciences Reviews, 7.3 (2019), 45–51
Wibowo, Ari, Widya Alawiyah, and Azriadi, ‘The Importance of Personal Data Protection in Indonesia’s Economic Development’, Cogent Social Sciences, 10.1 (2024)
Widiatedja, I. Gusti Ngurah Parikesit, and Neha Mishra, ‘Establishing an Independent Data Protection Authority in Indonesia: A Future–Forward Perspective’, International Review of Law, Computers & Technology, 37.3 (2023), 252–73
Willis, Brooke, Tunmin Jai, and Mitzi Lauderdale, ‘Trust and Commitment: Effect of Applying Consumer Data Rights on U.S. Consumers’ Attitudes toward Online Retailers in Big Data Era’, Journal of Consumer Behaviour, 20.6 (2021), 1575–90
Wodi, Alexander, ‘The EU General Data Protection Regulation (GDPR): Five Years After and the Future of Data Privacy Protection in Review’, SSRN Electronic Journal, 2023
Zhu, FangBing, and Zongyu Song, ‘Systematic Regulation of Personal Information Rights in the Era of Big Data’, SAGE Open, 12.1 (2022), 1–11
Zhuo, Ran, Bradley Huffaker, Kc Claffy, and Shane Greenstein, ‘The Impact of the General Data Protection Regulation on Internet Interconnection’, Telecommunications Policy, 45.2 (2021)
Zinovieva, Vera, Mikhail Shchelokov, and Evgeny Litvinovsky, ‘Legal Issues of Protection of Personal Data: Cases of Transport Data Leaks’, Transportation Research Procedia, 68 (2023), 461–67
Zuhroh, Nur Fatimatuz, and Tony Dwi Susanto, ‘Analysis of the Driving Factors for the Implementation of Personal Data Protection in Local Governments’, in AIP Conference Proceedings (American Institute of Physics Inc., 2023), mmcdlxxxii, 2021
- There are currently no refbacks.
Copyright (c) 2024 Wardah Yuspin, Trisha Rajput, Abhinayan Basu Bal, Kelik Wardiono, Absori Absori

This work is licensed under a Creative Commons Attribution 4.0 International License.