This study aims to construct the concepts of “preventive constitutional harm” and “digital sovereignty” as a new paradigm for personal data protection in international cooperation, analyze the normative gap between Article 62(2) (2) of the Personal Data Prot ection Law (PDP Law) against the constitutional standards of Article 28G(1) of the 1945 Constitution of the Republic of Indonesia, and to formulate a comprehensive constitutional protection model to fill this normative gap. This study employs a normative legal research method using a legislative approach, a case-based approach, a conceptual approach, and a comparative law approach to the EU’s GDPR, Brazil’s LGPD, and Indonesia’s Personal Data Protection Act. The findings indicate that Article 62( (2) of the PDP Law contains a multidimensional normative gap encompassing substantive, institution al, procedural-democratic, and remedial dimensions; thus, this study formulates the CDPFIC as an integrative model that positions digital sovereignty as an operational constitutional constraint on execu tive discretion in international cooperation regarding the transfer of personal data of Indonesian citizens.
Copyrights © 2026