Indonesian Political, Business & Finance News

Entering Buildings and Having Your ID Scanned: A Breach of Data Protection Laws?

| Source: CNBC Translated from Indonesian | Legal
Entering Buildings and Having Your ID Scanned: A Breach of Data Protection Laws?
Image: CNBC

Jakarta, CNBC Indonesia - Visitors to office buildings or public facilities are often required to submit their ID cards and have their faces photographed as a security measure. This practice has become commonplace when people want to enter certain public areas.

However, it turns out that this procedure is considered a violation of the principle of personal data protection. This was revealed by researcher from the Institute for Study and Advocacy of Society (ELSAM), Parasurama Pamungkas.

“Well, the collection of personal data that is not actually relevant to the activities we do, such as entering a tower, then registering an account, is essentially non-compliance with the controller’s adherence to the principles of personal data protection,” said Parasurama to CNBC Indonesia, some time ago.

Parasurama stated that collecting this type of data can be categorized as a violation because it does not meet several basic principles. One of them relates to the purpose of data collection which should be limited and relevant.

He believes that the data controller does not fulfill the element of legitimacy. This is because the personal data collected is not always relevant to the purpose of collecting the data, and has the potential to be used for other purposes.

Indonesia itself has privacy rules through the Personal Data Protection Law since 2022. This law strictly regulates the rights of Indonesian citizens as owners of personal data and sets out sanctions for companies and government institutions that fail to protect personal data.

Unfortunately, the implementation of this law is still hampered because the government has not established a supervisory body for personal data protection as mandated by the law. The supervisory body should have been established one year after the enactment of the law, which falls on October 17, 2024.

“And then using it for other purposes, and he also loses the legal basis to continue or process the irrelevant data,” he said.

The building managers should be able to find ways other than collecting ID cards or facial scans, in this case, methods that are not risky for the public. Building managers must also provide options so as not to restrict people’s activities in accessing the place.

Parasurama emphasized that privacy should be provided by default and by design. Protection of privacy must also be carried out by managers of restricted areas, including buildings.

“Well, this is actually part of a data breach, personal data protection. Because this is the same as digital platforms, how can we enjoy platforms that don’t have ads by paying for them,” he explained.

Contacted separately, Cybersecurity Expert from Vaksincom, Alfons Tanujaya explained that selfies and ID cards are not identification tools recognized by Dukcapil (Directorate General of Population and Civil Records).

In terms of security, Alfons said that it depends on the management of the data, such as how they store the data, whether it can be ensured that it is safe or not.

“Then whether it’s safe or not depends on the data manager, how he stores the data. If he doesn’t store it safely, if the data leaks, then it’s over,” said Alfons.

“What will also leak is the data, along with the photos, faces, selfies, which can be easily manipulated using AI,” he added.

View JSON | Print