Warning: Swapping KTP for Building Access and Facial Photos Violates the Law
The practice of exchanging identity cards such as KTP at front office or reception desks is frequently encountered when entering office buildings, apartments, and business districts in Indonesia. In fact, many building managements require visitors to be photographed or take a facial selfie before being allowed entry. However, this procedure, which has been considered normal for security reasons, potentially violates the law. The practice is deemed to breach the Personal Data Protection Law (UU PDP).
Researcher from the Institute for Policy Research and Advocacy (ELSAM), Parasurama Pamungkas, stressed that the act of collecting excessive personal data violates the basic principles of data protection. According to him, data collection must have a clear, limited purpose and be truly relevant to the need. When building management requests a KTP to record all its data or even takes a visitor’s facial photo, the action is considered to have exceeded the relevance of the building’s physical security.
“When the data is not relevant and is used for other purposes, the data controller loses its legal basis to continue processing that data,” he stated recently.
Beyond the legality issue, a latent danger lurking in this procedure is the security of the data storage itself. Most building managers are considered not yet to have adequate cyber security management systems to protect their visitors’ data. Cyber Security Expert from Vaksincom, Alfons Tanujaya, also highlighted the fatal risks behind this practice. According to him, the main problem is not just the initial data collection, but how such sensitive data is stored.
“Whether it is safe or not depends on the data manager, how they store that data. If they do not store it securely, then if the data leaks, it is over,” Alfons asserted. He warned that if a building manager’s database suffers a breach, the losses borne by the public would be massive. This is because the leaked data is no longer just a name or national identity number (NIK), but a complete package including the visitor’s facial photo or selfie.
In the current era of technological advancement, such visual data becomes a highly dangerous commodity if it falls into the wrong hands. “The data will also leak, along with the photo, the face, the selfie, which can then be manipulated using AI,” Alfons concluded. Victims’ faces could be manipulated using deepfake technology for various cybercrime activities, ranging from fraud to the creation of fictitious accounts. The public is therefore urged to be more vigilant and critical of any inspection procedure that requests excessive personal data in order to maintain the security of their respective digital privacy spaces.