General Background: The rapid digitalization of healthcare services after COVID-19 has expanded health data processing and increased privacy breach risks. Specific Background: Indonesia and Romania have developed comprehensive legal frameworks through the Indonesian Personal Data Protection Law, Health Law, GDPR, and Lege nr. 190/2018, yet both jurisdictions still face difficulties in protecting sensitive health information. Knowledge Gap: Existing studies have not sufficiently compared post-pandemic health data protection in Indonesia and Romania by examining supervisory institutions, law enforcement mechanisms, and the gap between legal norms and empirical implementation. Aims: This study analyzes and compares the regulation, enforcement mechanisms, supervisory capacity, and institutional governance of health data protection in Indonesia and Romania. Results: The findings show that both countries possess adequate normative frameworks but experience enforcement gaps caused by institutional weaknesses, inconsistent supervision, fragmented sectoral coordination, limited technical readiness, and weak compliance culture in healthcare institutions. Indonesia faces a critical institutional void because the independent data protection authority is not yet fully operational, while Romania faces selective and passive enforcement by ANSPDCP toward public healthcare institutions. Novelty: This study offers a comparative model that links regulatory design, health data governance, supervisory capacity, and institutional compliance in two distinct legal regimes: Indonesia’s national data sovereignty model and Romania’s GDPR-based free data flow model. Implications: Effective health data protection requires independent supervisory authorities, privacy by design, accessible dispute resolution, harmonized sectoral regulation, and sustainable institutional compliance culture.
Copyrights © 2026