Is the Use of Indonesian Citizens' Data to Train Foreign AI a Violation of Regulations?
The development of Artificial Intelligence (AI) technology is currently a primary focus for both the government and experts, following the increasing demand for data access.
The Deputy Minister of Communication and Digital, Nezar Patria, emphasised that the digital data and content of the Indonesian people have become a vital foundation for global AI development. According to him, data is no longer merely personal information but has transformed into the primary raw material for artificial intelligence. Every digital activity—ranging from location points and conversations to social media posts—becomes a digital footprint processed into high-value economic business and AI models.
“Global platforms such as Google, Meta, and TikTok collect and process data on a large scale. This data is then utilised for the development of technologies based on big data and artificial intelligence,” he stated in a written statement cited on Thursday.
He also warned that the issue extends beyond personal data protection. Public content, including journalistic works and academic writings, also faces the potential of being harvested to train AI machines without fair compensation or fair use mechanisms.
Currently, Nezar noted that the Ministry of Communication and Digital is reviewing the national regulatory framework to respond to the challenges of new technologies, including AI. The government is also studying data governance practices in the European Union, which prioritises the protection of citizens’ rights within the digital ecosystem.
The Need for Specific AI Regulation
Separately, the Executive Director of Catalyst Policy-Works, Wahyund Djafar, assessed that the Personal Data Protection Law (UU PDP) already contains rules regarding the use of personal data for automatic processing, including for AI machine learning needs. Under the UU PDP, the use of data for automatic profiling or the automatic processing of sensitive data must undergo a Data Protection Impact Assessment (DPIA).
Nevertheless, Wahyudi believes that the regulations within the UU PDP alone are not strong enough to serve as a comprehensive legal umbrella for AI management. The government is reportedly still pushing for the drafting of regulations in the form of a Presidential Regulation regarding the AI Roadmap, alongside AI Ethics guidelines.
Although one of the principles of AI ethics is closely related to data protection and privacy, Indonesia still requires a legal instrument that specifically regulates artificial intelligence, as the current approach is limited to ethics.
“In the future, that may not be sufficient. This is why we are beginning to consider how to develop a regulation that specifically governs AI,” Wahyudi told CNBC Indonesia.
As a comparison, Wahyudi cited the steps taken by the European Union. The existence of personal data protection regulations, such as the EU General Data Protection Regulation (EU GDPR), is considered insufficient to mitigate all the complexities of AI development. Consequently, the European Union eventually passed a specific regulation titled the EU AI Act in 2024, which is scheduled to come into effect in 2027.
On the other hand, Wahyudi believes that the process of formulating AI regulations in Indonesia should also learn from the implementation experience of the UU PDP. He noted that the effectiveness of applying personal data protection rules will be a crucial foundation for formulating the substance and scope of future AI regulations. Therefore, it is argued that Indonesia needs to accelerate the maturation of compliance standards regarding the UU PDP.
“What we need today is a more binding AI regulation, which can only be well-built when we have gained sufficient experience in the operationalisation or implementation of the Personal Data Protection Law,” he concluded.