Limitations On Which Data Is Defined As Personal Data Based On Law Number 27 Of 2022 Concerning Personal Data Protection
According to Article 4 Law Number 27/2022 on Data Privacy Protection (“UU PDP”) governs that characteristic and classification, namely:
- Specific personal data;
- General personal data.
Specific personal data, includes:
- Data and Health Information;
- Biometric data;
- Genetic data;
- Criminal Records;
- Child data;
- Personal data informations; and/or
- Others data in accordance with the provisions of laws and regulations.
General personal data, includes:
- Full name;
- Gender;
- Nationality;
- Religion;
- Marital Status;
- Personal data combined to identify an individual.
So based on the provisions in these articles, the limit for something being said to be personal data is as long as the data concerns a person’s identity or if put together can identify a person.
Then the further question arises, who is obliged to protect this data?
In laws and regulations, Personal Data Controllers and Personal Data Processors are obliged to protect Personal Data in accordance with the consent of the Personal Data Subject as outlined in the form of an Agreement. Personal Data Controllers and Personal Data Processors include Individuals, Public Bodies and International Organizations.
Basically, protecting personal data is an implementation of human rights, namely the right to privacy. This means that everyone is obliged to maintain these rights without having to write them down in an agreement. So that automatically every time Personal Data is given to another party, the recipient party is obliged to protect that personal data because it is every human being’s obligation to protect human rights, both their own and those of others.
If personal data has been spread to the public, it does not mean that their status has changed from private data to public data or because their personal data is public, which means the public is allowed to know about it. This is because the nature of personal data is private, which means that not everyone has the right to obtain and/or view it and requires permission from the Data Owner whether he wants his data to be made public. Refers to the rights possessed by the holder of personal data, namely the Right to be Forgotten, that he has the right to request that his personal data be deleted.
[1] Pasal 35 UU PDP
[2] Pasal 19 UU PDP
[3] Pasal 8 UU PDP