This study aims to analyze the extent to which the political will of the Ministry of Communication and Digital Affairs (Komdigi) affects the effectiveness of cybersecurity governance over personal data in Indonesia, using the 2022 Bjorka data hacking case as the case study. The method used is descriptive qualitative, with informants selected purposively from an internal representative of Komdigi and the civil society organization SAFENet, combined with secondary data from official documents and media reports, analyzed through governance network theory and Brinkerhoff's theory of political will. The results show that personal data security governance in Indonesia following the Bjorka case is marked by unresolved institutional fragmentation between Komdigi and the National Cyber and Crypto Agency (BSSN), and by a political will that remains symbolic rather than substantive, reflected in reactive policy initiatives, minimal civil society involvement in drafting implementing regulations, inconsistent budget allocation, the absence of credible sanctions due to the independent data protection authority not yet being established, and recurring major data breaches after Bjorka. The study also finds that leaked personal data has been used as an instrument of repression against critical citizens, indicating that the consequences of weak data governance extend beyond economic loss into the political sphere. It is concluded that strengthening Indonesia's cybersecurity governance requires substantive and sustained political will, rather than merely formal regulatory products on paper.
Copyrights © 2026