Sunarso Sunarso
Sekolah Tinggi Ilmu Hukum Sumpah Pemuda

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Pengaturan Normatif Perlindungan Data Pribadi dalam Transaksi Bisnis Digital di Indonesia Angga Pramudia Natatur; Sunarso Sunarso; Muhammad Meiddy Gunandi; Aldhi Arrahman
Lex Stricta : Jurnal Ilmu Hukum Vol. 5 No. 1 (2026)
Publisher : Sekolah Tinggi Ilmu Hukum Sumpah Pemuda

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.46839/lexstricta.v5i1.1858

Abstract

This study on Personal Data Protection in Digital Business Transactions in Indonesia is a critical analysis of the intersection between digital sovereignty, the protection of human rights, and legal certainty in the digital economy. This research is motivated by the digital transformation, which has increased the risk of personal data breaches in Indonesia. Although Law No. 27 of 2022 has been enacted, its effectiveness is hampered by institutional constraints and low digital literacy. This study aims to analyze the effectiveness of the implementation of the Personal Data Protection Law and its alignment with international standards such as the General Data Protection Regulation. Using a normative legal approach, the research findings reveal a functional legal vacuum resulting from the absence of an independent supervisory body. An analysis of Lawrence Friedman’s legal systems theory highlights the unpreparedness of the legal structure and culture, while Gustav Radbruch’s theory identifies legal lacunae in cross-border transactions. This article offers novel insights through the reconstruction of legal norms, including: a model for the functional harmonization of the Personal Data Protection Act and the General Data Protection Regulation; the strengthening of a hybrid-autonomous supervisory authority; the formulation of cross-border data transfer rules; and the application of the doctrine of strict liability to digital platforms. The study’s conclusion underscores the need for regulatory synchronization to transform declarative norms into instruments that ensure legal certainty and genuine accountability on the part of data controllers.