Personal Data Protection and Legal Accountability in the Digital Transformation of Public and Private Institutions
DOI:
https://doi.org/10.59890/ijist.v4i9.51Keywords:
Personal Data Protection, Legal Liability, Digital Transformation, Accountability, InstitutionsAbstract
Digital transformation in public and private institutions increases the processing of personal data while increasing the risk of privacy violations and unclear legal liability. This research aims to analyze the protection of personal data and the construction of institutional legal accountability in the implementation of digital systems. The research uses normative legal methods with legislative, conceptual, and comparative approaches. Data in the form of primary and secondary legal materials were collected through literature studies and analyzed qualitatively-prescriptively, without involving respondents or informants. The results show that the effectiveness of data protection depends on data controller compliance, processing security, clarity of legal obligations, and effective enforcement mechanisms. The research concludes that strengthening institutional accountability, data governance, and law enforcement consistency is needed to ensure the protection of data subjects' rights in digital transformation.
References
'Aisy, F. R., Maskur, M. A., & Amiruddin, A. M. A. (2025). Establishing Indonesia’s personal data protection agency: Comparative administration sanctions enforcement from Ireland, Australia, and Singapore. Journal of Indonesian Legal Studies, 10(1), 431–482. https://doi.org/10.15294/jils.v10i1.13755
Alatas, H. H. R. A., & Djajaputra, G. (2025). Examining Indonesian government accountability and mitigation measures in the 2024 taxpayer identification number data breach. Jurnal Ilmu Hukum Kyadiren, 7(2), 1234–1248. https://doi.org/10.46924/jihk.v7i2.385
Aura, A., Priowirjanto, E. S., & Dewi, C. T. I. (2025). Privacy protection guarantee for data hacking victims according to Indonesian law. Padjadjaran Journal of International Law, 9(1), 1–15. https://doi.org/10.23920/pjil.v8i2.1823
Badriah, L., Indiahono, D., & Sukarso. (2024). Akuntabilitas dalam kebijakan perlindungan data pribadi di Indonesia: Belajar dari Korea Selatan dan Singapura. Matra Pembaruan: Jurnal Inovasi Kebijakan, 8(2), 89–102. https://doi.org/10.21787/mp.8.2.2024.89-102
Buckley, G., Caulfield, T., & Becker, I. (2024). GDPR and the indefinable effectiveness of privacy regulators: Can performance assessment be improved? Journal of Cybersecurity, 10(1), tyae017. https://doi.org/10.1093/cybsec/tyae017
Byrne, W. H., & Olsen, H. P. (2024). Doctrinal legal science: A science of its own? Canadian Journal of Law & Jurisprudence, 37(2), 343–367. https://doi.org/10.1017/cjlj.2024.16
Coche, E., Kolk, A., & Ocelík, V. (2024). Unravelling cross-country regulatory intricacies of data governance: The relevance of legal insights for digitalization and international business. Journal of International Business Policy, 7, 112–127. https://doi.org/10.1057/s42214-023-00172-1
Daud, M. (2025). A legal framework for public sector data sharing in Malaysia: The clash between data protection, privacy and public interest. IIUM Law Journal, 33(2), 279–320. https://doi.org/10.31436/iiumlj.v33i2.1072
Finck, M. (2021). Cobwebs of control: The two imaginations of the data controller in EU law. International Data Privacy Law, 11(4), 333–347. https://doi.org/10.1093/idpl/ipab017
Georgiadis, G., & Poels, G. (2022). Towards a privacy impact assessment methodology to support the requirements of the General Data Protection Regulation in a big data analytics context: A systematic literature review. Computer Law & Security Review, 44, 105640. https://doi.org/10.1016/j.clsr.2021.105640
Hof, J. P. (2024). Enforcement of data breaches in the Dutch and British healthcare sector: A contribution to clarifying requirements of data protection by design? International Review of Law, Computers & Technology, 38(3), 327–345. https://doi.org/10.1080/13600869.2024.2324544
Karjalainen, T. (2022). All talk, no action? The effect of the GDPR accountability principle on the EU data protection paradigm. European Data Protection Law Review, 8(1), 19–30. https://doi.org/10.21552/edpl/2022/1/6
Kurtz, C., Wittner, F., Semmann, M., Schulz, W., & Böhmann, T. (2022). Accountability of platform providers for unlawful personal data processing in their ecosystems: A socio-techno-legal analysis of Facebook and Apple’s iOS according to GDPR. Journal of Responsible Technology, 9, 100018. https://doi.org/10.1016/j.jrt.2021.100018
Labadie, C., & Legner, C. (2023). Building data management capabilities to address data protection regulations: Learnings from EU-GDPR. Journal of Information Technology, 38(1), 16–44. https://doi.org/10.1177/02683962221141456
Li, Y., Yang, R., & Lu, Y. (2024). A privacy risk identification framework of open government data: A mixed-method study in China. Government Information Quarterly, 41(1), 101916. https://doi.org/10.1016/j.giq.2024.101916
Nyathi, M. (2023). Re-asserting the doctrinal legal research methodology in the South African academy: Navigating the maze. South African Law Journal, 140(2), 365–386. https://doi.org/10.47348/SALJ/v140/i2a5
Rahman, F., & Mulyani, C. K. (2025). Minimising unnecessary restrictions on cross-border data flows? Indonesia’s position and challenges post personal data protection act enactment. International Review of Law, Computers & Technology, 39(2), 281–300. https://doi.org/10.1080/13600869.2024.2359901
Susilo, D. D. B. (2025). Pelindungan hukum data pribadi terhadap data peminjam online dalam perspekstif hukum perjanjian [Master's thesis, Program Studi Magister Hukum, Universitas Mahasaraswati, Denpasar].
Susilo, D. D. B., Perbawa, I. K. S. L. P., & Wedha, Y. Y. (2025). Legal aspects of agreement in the protection of personal data on the withdrawal of online loan borrower information. FireNav: Financial Resilience and National Values Journal, 1(1), 60-73.
Susilo, D. D. B. (2026). Tanggung jawab hukum BPR atas profiling skor kredit berbasis AI berdasarkan UU PDP. JPGI (Jurnal Penelitian Guru Indonesia), 11(2), 1314-1325. https://doi.org/10.29210/027185jpgi0005
van Gestel, R. (2023). Quality, methodology, and politics in doctrinal legal scholarship. Law and Method, 2023, 1–24. https://doi.org/10.5553/REM/.000070
Widiatedja, I. G. N. P., & Mishra, N. (2023). Establishing an independent data protection authority in Indonesia: A future-forward perspective. International Review of Law, Computers & Technology, 37(3), 252–273. https://doi.org/10.1080/13600869.2022.2155793
Wong, B. (2021). Problems with controller-based responsibility in EU data protection law. International Data Privacy Law, 11(4), 375–387. https://doi.org/10.1093/idpl/ipab014
Yeung, K., & Bygrave, L. A. (2022). Demystifying the modernized European data protection regime: Cross-disciplinary insights from legal and regulatory governance scholarship. Regulation & Governance, 16(1), 137–155. https://doi.org/10.1111/rego.12401
Zaguir, N. A., Magalhães, G. H. de, & Spínola, M. (2024). Challenges and enablers for GDPR compliance: Systematic literature review and future research directions. IEEE Access, 12, 81608–81630. https://doi.org/10.1109/ACCESS.2024.3406724
Zhou, C., Barati, M., & Shafiq, O. (2023). A compliance-based architecture for supporting GDPR accountability in cloud computing. Future Generation Computer Systems, 145, 104–120. https://doi.org/10.1016/j.future.2023.03.021
Peraturan Perundang-undangan dan Instrumen Hukum
European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
Indonesia. (2019). Peraturan Pemerintah Republik Indonesia Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik.
Indonesia. (2022). Undang-Undang Republik Indonesia Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi.
Indonesia. (2024). Undang-Undang Republik Indonesia Nomor 1 Tahun 2024 tentang Perubahan Kedua atas Undang-Undang Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik.






