{
    "success": true,
    "data": {
        "id": 1853305,
        "msgid": "warning-swapping-ktp-for-building-access-and-facial-photos-violates-the-law-1783731035",
        "date": "2026-07-11 07:15:00",
        "title": "Warning: Swapping KTP for Building Access and Facial Photos Violates the Law",
        "author": "",
        "source": "CNBC",
        "tags": "",
        "topic": "Legal",
        "summary": "The common practice of surrendering identity cards or having one's photo taken to enter office buildings in Indonesia violates the Personal Data Protection Law, according to legal experts. Researchers warn that excessive data collection lacks legal basis and exposes visitors to severe risks, including deepfake manipulation, if the poorly secured data is breached.",
        "content": "<p>The practice of exchanging identity cards such as KTP at front office\nor reception desks is frequently encountered when entering office\nbuildings, apartments, and business districts in Indonesia. In fact,\nmany building managements require visitors to be photographed or take a\nfacial selfie before being allowed entry. However, this procedure, which\nhas been considered normal for security reasons, potentially violates\nthe law. The practice is deemed to breach the Personal Data Protection\nLaw (UU PDP).<\/p>\n<p>Researcher from the Institute for Policy Research and Advocacy\n(ELSAM), Parasurama Pamungkas, stressed that the act of collecting\nexcessive personal data violates the basic principles of data\nprotection. According to him, data collection must have a clear, limited\npurpose and be truly relevant to the need. When building management\nrequests a KTP to record all its data or even takes a visitor\u2019s facial\nphoto, the action is considered to have exceeded the relevance of the\nbuilding\u2019s physical security.<\/p>\n<p>\u201cWhen the data is not relevant and is used for other purposes, the\ndata controller loses its legal basis to continue processing that data,\u201d\nhe stated recently.<\/p>\n<p>Beyond the legality issue, a latent danger lurking in this procedure\nis the security of the data storage itself. Most building managers are\nconsidered not yet to have adequate cyber security management systems to\nprotect their visitors\u2019 data. Cyber Security Expert from Vaksincom,\nAlfons Tanujaya, also highlighted the fatal risks behind this practice.\nAccording to him, the main problem is not just the initial data\ncollection, but how such sensitive data is stored.<\/p>\n<p>\u201cWhether it is safe or not depends on the data manager, how they\nstore that data. If they do not store it securely, then if the data\nleaks, it is over,\u201d Alfons asserted. He warned that if a building\nmanager\u2019s database suffers a breach, the losses borne by the public\nwould be massive. This is because the leaked data is no longer just a\nname or national identity number (NIK), but a complete package including\nthe visitor\u2019s facial photo or selfie.<\/p>\n<p>In the current era of technological advancement, such visual data\nbecomes a highly dangerous commodity if it falls into the wrong hands.\n\u201cThe data will also leak, along with the photo, the face, the selfie,\nwhich can then be manipulated using AI,\u201d Alfons concluded. Victims\u2019\nfaces could be manipulated using deepfake technology for various\ncybercrime activities, ranging from fraud to the creation of fictitious\naccounts. The public is therefore urged to be more vigilant and critical\nof any inspection procedure that requests excessive personal data in\norder to maintain the security of their respective digital privacy\nspaces.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/warning-swapping-ktp-for-building-access-and-facial-photos-violates-the-law-1783731035",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}