The Role of the Supervisory Agency in Enforcing Privacy and Data Security Laws in Indonesia
Main Article Content
Abstract
The development of information technology and digitalization has increased the volume and complexity of personal data processing in Indonesia, thus posing serious challenges related to privacy protection and data security. In this context, the existence of a supervisory body plays a strategic role in ensuring regulatory compliance, particularly following the enactment of the Personal Data Protection Law (PDP Law). This study aims to analyze the role of the supervisory body in enforcing privacy and data security laws in Indonesia, including its supervisory functions, law enforcement, and the imposition of administrative sanctions. The method used is a normative juridical approach by analyzing laws and regulations and related literature. The results show that the supervisory body plays a significant role in creating legal certainty, raising awareness among business actors and the public, and encouraging the implementation of data protection principles. However, the effectiveness of this role still faces various obstacles, such as limited resources, inter-agency coordination, and low digital literacy among the public. Therefore, institutional strengthening, comprehensive derivative regulations, and increased human resource capacity are needed to achieve optimal personal data protection in Indonesia.
Article Details

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
References
Ali, Z. (2022). Metode penelitian hukum. Sinar Grafika.
Bennett, C. J. (2019). Data protection and privacy: International perspectives and reforms. Information Polity, 24(2), 123–135. https://doi.org/10.3233/IP-190120
Brown, I. (2021). Regulation and enforcement of data protection: The role of supervisory authorities. Computer Law & Security Review, 41, 105567. https://doi.org/10.1016/j.clsr.2021.105567
Bygrave, L. A. (2021). Data privacy law: An international perspective (2nd ed.). Oxford University Press.
Cate, F. H. (2020). The limits of notice and choice in data protection. IEEE Security & Privacy, 18(2), 59–64. https://doi.org/10.1109/MSEC.2019.2961702
Fikri, R. A., Siregar, M. A., Rambe, M. J., & Syaharani, N. (2024, August). Strategy for Handling Criminal Acts of Fighting Due to Juvenile Delinquency in Medan City through Criminal Law Policy. In International Conference Epicentrum of Economic Global Framework (pp. 340-346).
Gellert, R. (2016). Data protection: A risk regulation? Computer Law & Security Review, 32(3), 503–515. https://doi.org/10.1016/j.clsr.2016.02.005
Greenleaf, G. (2018). Global data privacy laws 2017: 120 national data privacy laws, including Indonesia. Privacy Laws & Business International Report, 145, 10–13.
Harahap, M. Y. (2023). Pengawasan dalam perlindungan data pribadi di Indonesia. Jurnal Hukum Ius Quia Iustum, 30(1), 45–60.
Hidayat, R. (2023). Tantangan implementasi undang-undang perlindungan data pribadi di Indonesia. Jurnal Legislasi Indonesia, 20(2), 101–115.
Indonesia. (2022). Undang-Undang Nomor 27 Tahun 2022 tentang Perlindungan Data Pribadi.
Indrawan, M. I., Fikri, R. A., Hasibuan, H. A., & Widianto, D. E. (2025, October). Building An Adaptive Entrepreneurial Mindset: The Role Of Dropshipping And Affiliate Marketing In Industry 4.0 Education. In Proceedings of International Conference on Islamic Community Studies (pp. 2273-2282).
Kuner, C. (2020). Reality and illusion in EU data transfer regulation post Schrems. German Law Journal, 21(5), 881–918. https://doi.org/10.1017/glj.2020.50
Lestari, D. (2022). Perlindungan data pribadi dalam perspektif hukum Indonesia. Jurnal Rechts Vinding, 11(3), 305–320.
Lubis, M. (2023). Koordinasi kelembagaan dalam penegakan hukum data pribadi. Jurnal Hukum dan Pembangunan, 53(1), 77–92.
Marzuki, P. M. (2021). Penelitian hukum (edisi revisi). Kencana.
Nasution, A. (2022). Peran regulator dalam pengawasan data digital. Jurnal Ilmu Hukum, 18(2), 210–225.
Nasution, H. A. R., & Fikri, R. A. (2023). Hukum Tekhnologi Dan Informasi. Penerbit Tahta Media
Putri, S. (2022). Kebocoran data pribadi dan implikasinya di Indonesia. Jurnal Keamanan Informasi, 8(1), 55–68.
Rahardjo, S. (2021). Ilmu hukum. Citra Aditya Bakti.
Rahman, F. (2022). Penegakan hukum dalam perlindungan data pribadi. Jurnal Yuridika, 37(2), 145–160.
Rahmayanti, R. (2021). Return of Corruption Assets toward Criminal Actions of Office Abuse. Budapest International Research and Critics Institute-Journal (BIRCI-Journal), 4(2), 2114-2120.
Santoso, B. (2021). Pendekatan normatif dalam penelitian hukum. Jurnal Hukum, 15(1), 1–10.
Schwartz, P. M. (2019). Global data privacy: The EU way. New York University Law Review, 94(4), 771–832.
Setiawan, A. (2023). Implementasi undang-undang perlindungan data pribadi di Indonesia. Jurnal Hukum dan Regulasi, 5(2), 89–104.
Simanjuntak, R. (2022). Kapasitas kelembagaan dalam pengawasan data pribadi. Jurnal Administrasi Publik, 12(3), 233–248.
Siregar, M. A., Adrian, R. F., & Rambe, M. J. (2023). Menelusuri Perjalanan Lahirnya Konsep Sistem Hukum Pidana Dan Hukum Pidana Di Indonesia. Penerbit Tahta Media.
Soekanto, S. (2019). Pengantar penelitian hukum. UI Press.
Sugiyono. (2020). Metode penelitian kualitatif, kuantitatif, dan R&D. Alfabeta.
Tanjung, H. (2023). Penguatan kelembagaan dalam perlindungan data pribadi. Jurnal Kebijakan Publik, 14(1), 66–80.
Voigt, P., & von dem Bussche, A. (2017). The EU General Data Protection Regulation (GDPR): A practical guide. Springer.
Warren, S. D. (2022). The right to privacy revisited in modern data protection. Harvard Law Review, 135(6), 1935–1950.
Yusuf, M. (2023). Perlindungan data pribadi sebagai hak asasi manusia. Jurnal HAM, 14(2), 120–135.