Observer: Implementation of Personal Data Protection Law for MSMEs Needs to Align with Business Scale
MSMEs that only store customer data for simple transactions certainly cannot be treated the same as companies that process millions of data points or large-scale sensitive data.
Jakarta (ANTARA) - Digital economy observer from the University of Indonesia, Heru Sutting, assesses that the implementation of the Personal Data Protection Law (UU PDP) for micro, small, and medium enterprises (MSMEs) needs to be adjusted to the scale of the business and the level of data processing risk, so that consumer protection obligations do not hinder the digitalisation process.
Heru stated that the fundamental principles of personal data protection must still be applied to all business actors, but the depth of obligations and oversight mechanisms can be adjusted according to the scale of the business, the type of data managed, and the level of risk.
“In my opinion, the government needs to implement a risk-based and business-scale principle. MSMEs that only store customer data for simple transactions certainly cannot be treated the same as companies that process millions of data points or sensitive data on a large scale,” he told ANTARA in Jakarta on Thursday.
Heru noted that this risk-based approach is considered important so that the UU PDP does not only function as a consumer protection instrument, but can also support the development of the digital economy, particularly for MSMEs currently undergoing digital transformation.
He also assessed that the government needs to provide simple and affordable compliance mechanisms for MSMEs, without reducing the core principles of personal data protection. Such ease is important considering that the capacity of MSMEs is highly diverse.
Support can be provided through the provision of privacy policy templates, examples of data usage consent forms, data management guidelines, simple security standards, and easy-to-use compliance checklists for business actors.
Furthermore, the government can collaborate with MSME associations, digital platforms, and technology providers to provide training and assistance.
“With an approach like this, MSMEs will not need to start from scratch. The goal is to make compliance easy, affordable, and realistic to implement,” said Heru.
He warned that implementing rules that are too complex and expensive has the potential to become a barrier for MSMEs wishing to enter the digital ecosystem. Small business actors may choose to delay digitalisation if they perceive that compliance with data protection requires resources that are beyond their capacity.
Conversely, ease of implementing the UU PDP can help MSMEs build data governance from the start while simultaneously increasing customer trust in the businesses they operate.
Therefore, Heru believes that the implementation of the UU PDP should be positioned as part of strengthening the digital business culture of MSMEs, with personal data protection regulatory mechanisms that are realistic and appropriate for the capabilities of business actors.