Emanuel Ristian Handoyo
Sistem Informasi, Fakultas Teknologi Industri, Universitas Atma Jaya Yogyakarta, Yogyakarta, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

A Static Analysis of Privacy by Design Compliance in Indonesian Quick-Service Restaurant Applications Emanuel Ristian Handoyo; Flourensia Sapty Rahayu
IDEALIS : InDonEsiA journaL Information System Vol. 9 No. 2 (2026): Jurnal IDEALIS Juli 2026
Publisher : Universitas Budi Luhur

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.36080/idealis.v9i2.3825

Abstract

The adoption of Quick-Service Restaurant (QSR) apps in Indonesia tripled from 2020 to the following three years. However, technical privacy audits of local apps remain very limited, and no research has systematically evaluated QSR apps in Indonesia using technical methods. To address this gap as the study's objective, the privacy compliance of QSR applications was systematically evaluated. Methodologically, the PbD-MASVS-MobSF evaluation framework was implemented, wherein Privacy by Design (PbD) principles, OWASP MASVS privacy controls, and Mobile Security Framework (MobSF) processes were integrated. As a sample, seven QSR apps were analysed, and their privacy findings were compared to the provisions of Law No. 27 of 2022 on Personal Data Protection (UU PDP). Regarding the key results, it was found that the apps were at a MEDIUM to HIGH risk level, with MobSF scores of 39-54 out of 100. The compliance analysis found that the apps consistently failed to meet six of the ten MobSF subprocesses. Meanwhile, strong compliance was only identified in the absence of API access for device identification. These findings indicate that privacy risks in the Indonesian QSR sector are structural and sectoral. Crucially, because only static analysis was utilised in this assessment, the findings are considered indicative rather than conclusive, and legal non-compliance with the PDP Law cannot be independently established. As a primary contribution, an operational framework that connects static analysis results, privacy design principles, and national regulatory requirements is provided as a reference for application developers, privacy auditors, and regulators.