Habiba Salsabil Ananda Ghofar
Unknown Affiliation

Published : 2 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search

Joint Data Controller Responsibility in OSS RBA System Interoperability after the Personal Data Protection Law Enactment Deva Alfianto Supardi; Habiba Salsabil Ananda Ghofar; Daffa Hakima Nur Dzaki; Shinta Hadiyantina; Muhammad Reza Magistra
Kertha Patrika Vol. 48 No. 1 (2026): Recalibrate Indonesia Law based on Legal Reform in Specific Sectors
Publisher : Faculty of Law, Udayana University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24843/KP.2026.v48.i01.p01

Abstract

The business licensing reform enacted through Law Number 11 of 2020 concerning Job Creation has given rise to the Risk-Based Online Single Submission (OSS RBA) system, which relies on real-time data interoperability from various government agencies. The ratification of Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) introduces a new legal regime that creates ambiguity regarding the legal status of the parties within the OSS RBA ecosystem. This research aims to analyze the legal qualification of the parties involved in personal data processing within the ecosystem, evaluate the application of the Joint Controllership concept in OSS RBA interoperability, and formulate a mechanism for allocating legal responsibility in the event of personal data protection failures. The research employs a normative juridical method with statutory and conceptual approaches. The result indicate that the relationship between the Ministry of Investment/BKPM and the data source agencies is more appropriately qualified as Joint Controllers, as they collectively determine the purposes and means of personal data processing. A legal void exists in the regulation of joint controllership within the OSS RBA. The absence of agreements or derivative technical regulations governing the allocation of responsibility creates ambiguity that can be detrimental to data subjects. Therefore, derivative regulations are necessary to stipulate in detail the joint controllership mechanism and to mandate the preparation of Data Sharing Agreements (DSAs) between agencies, which would define the responsibilities of each party in accordance with the provisions of the PDP Law.
Joint Data Controller Responsibility in OSS RBA System Interoperability after the Personal Data Protection Law Enactment Deva Alfianto Supardi; Habiba Salsabil Ananda Ghofar; Daffa Hakima Nur Dzaki; Shinta Hadiyantina; Muhammad Reza Magistra
Kertha Patrika Vol. 48 No. 1 (2026): Recalibrate Indonesia Law based on Legal Reform in Specific Sectors
Publisher : Faculty of Law, Udayana University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24843/KP.2026.v48.i01.p01

Abstract

The business licensing reform enacted through Law Number 11 of 2020 concerning Job Creation has given rise to the Risk-Based Online Single Submission (OSS RBA) system, which relies on real-time data interoperability from various government agencies. The ratification of Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) introduces a new legal regime that creates ambiguity regarding the legal status of the parties within the OSS RBA ecosystem. This research aims to analyze the legal qualification of the parties involved in personal data processing within the ecosystem, evaluate the application of the Joint Controllership concept in OSS RBA interoperability, and formulate a mechanism for allocating legal responsibility in the event of personal data protection failures. The research employs a normative juridical method with statutory and conceptual approaches. The result indicate that the relationship between the Ministry of Investment/BKPM and the data source agencies is more appropriately qualified as Joint Controllers, as they collectively determine the purposes and means of personal data processing. A legal void exists in the regulation of joint controllership within the OSS RBA. The absence of agreements or derivative technical regulations governing the allocation of responsibility creates ambiguity that can be detrimental to data subjects. Therefore, derivative regulations are necessary to stipulate in detail the joint controllership mechanism and to mandate the preparation of Data Sharing Agreements (DSAs) between agencies, which would define the responsibilities of each party in accordance with the provisions of the PDP Law.