Read Time: 5 minutes
Every time you fill out a form, sign up for an app, or hand over your ID, you are sharing personal information that others can collect, use, and distribute. Data privacy is your right to control how that information is handled. Understanding that right is the first step to protecting it.
What is Personal Data?
Personal data is any information that can identify you, including your name, address, phone number, date of birth, email, financial details, and location. In Indonesia, your KTP consolidates much of this in one document, making it particularly sensitive.
What makes KTP data especially significant is that it is permanent. Unlike a password that can be reset or a phone number that can be changed, the information on your KTP cannot be altered once it has been exposed, making any compromise a long-term concern.
Why Data is Collected?
Data is big business. Companies, data brokers, and advertisers collect and sell personal information to build profiles, target advertising, and make decisions about you. Much of this happens without direct awareness, and the more your data circulates, the more difficult it becomes to manage.
Personal Data Protection
Three reasons to take data privacy seriously:
-
Security: Personal data in the wrong hands enables identity theft, financial fraud, and social engineering. Attackers use personal details to impersonate individuals, open accounts without authorization, or manipulate people within a trusted network.
-
Choice: Privacy gives individuals the right to determine what others know about them and how that information is used.
-
Balancing Privacy and Convenience: Sharing some data is often necessary for convenience, but understanding what is being shared enables informed decisions rather than automatic ones.
What You Can Do
-
Ask the reason why your personal data is needed and how it will be stored before handing it over or sharing a photograph of it
-
Understand that some data sharing is unavoidable. Certain services require personal information to function, so focus on what you can control.
-
When mobile apps or websites request access, ask yourself whether the permission makes sense for the service
-
Regularly review app permissions and remove access that is no longer necessary
-
Check privacy settings on platforms and services you use
-
Verify that any service requesting your personal data is legitimate before providing it
Personal Data Protection Framework
Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection will officially came into force on 16 January 2027. Under this new framework, Personal Data Protection Institution (“Institution”) will oversee compliance and impose sanctions on Personal Data Controllers (“Controllers”) and Personal Data Processors (“Processors”).
For years, Crowe has supported organizations building data security and privacy programs however, we believe it remains a shared responsibility that the program should start from the individual who own the data (“Owner”).