Failing to Protect Personal Data: Key Aspects of Electronic System Operators’ Agreements


  • Julienna Hartono Universitas Airlangga, Indonesia
  • Angelica Milano A.W. Universitas Airlangga, Indonesia
  • Xavier Nugraha Universitas Airlangga, Indonesia
  • Stefania Arshanty Felicia Vrije Universiteit Amsterdam, Netherlands



Electronic System Operators, Data Protection, Personal Data Processing Agreement


The rise of information technology has led to an increase in personal data processing by Electronic System Operators (ESOs). To ensure compliance with personal data protection principles, a personal data processing agreement is necessary for the involved parties: the controllers and processors of personal data. This agreement governs the ESO's liability in the event of a data protection failure. Regulating this aspect within a legal framework provides legal certainty and safeguards for all parties involved. By comparing personal data protection laws in Indonesia and the European Union, this article examines two key issues: the aspects of personal data processing agreements and the liability of ESOs in the event of data protection failure. The goal is to analyze the legal similarities and differences surrounding personal data protection.


Anand, G. (2011). Prinsip Kebebasan Berkontrak dalam penyusunan kontrak. Yuridika, 26(2), 91-101.
Baiq, P. A. (2021). Perlindungan Hukum terhadap Data Pribadi dalam Transaksi E-Commerce: Perspektif Hukum Islam dan Hukum Positif. DIKTUM: Jurnal Syariah dan Hukum, 19(2), 149-165.
Bakarbessy, L., & Anand, G. (2018). Buku Ajar Hukum Perikatan. Sidoarjo: Zifatama Jawara.
Brkan, M. (2019). The essence of the fundamental rights to privacy and data protection: finding the way through the maze of the CJEU’s constitutional reasoning. German Law Journal, 20(6), 864-883.
Colcelli, V. (2019). Joint Controller Agreement Under Gdpr. EU and comparative law issues and challenges series (ECLIC), 3, 1030-1047.
Cruz, R, D, L. (2020). Data Protection Contracts — What Tends To Be Missing and What To Do About It. Pivacy and Data Protection, 20(8), 2-17.
Disemadi, H. S. (2021). Urgensi regulasi khusus dan pemanfaatan artificial intelligence dalam mewujudkan perlindungan data pribadi di Indonesia. Jurnal Wawasan Yuridika, 5(2), 177-199.
Disemadi, H. S. (2022). Lenses of Legal Research: A Descriptive Essay on Legal Research Methodologies. Journal of Judicial Review, 24(2), 289-304.
GDPR Register. (2022). "Data Processing Agreement (DPA), online: GDPR Register <>.
Hernoko, A, Y. (2014). Hukum Perjanjian: Asas Proporsionalitas Dalam Kontrak Komersial. Jakarta: Prenadamedia Group.
Kadly, E. I., Rosadi, S. D., & Gultom, E. (2021). Keabsahan Blockchain-Smart Contract Dalam Transaksi Elektronik: Indonesia, Amerika Dan Singapura. Jurnal Sains Sosio Humaniora, 5(1), 199-212.
Kurniawan, F., Nugraha, X., Abrianto, B. O., & Ramadhanti, S. (2020). The Right To Access Banking Data In a Claim For A Divisio Of Combined Assets That Is Filed Separately From A Divorce Claim. Yustisia Jurnal Hukum, 9(1), 37-45.
Muhammad, M. O., & Nugroho, L. D. (2021). Perlindungan Hukum Terhadap Pengguna Aplikasi E-Commerce yang Terdampak Kebocoran Data Pribadi. Jurnal Pamator: Jurnal Ilmiah Universitas Trunojoyo, 14(2), 165-174.
Nemčeková, I. (2019), Liability of Joint Controllers in the Light of the CJEU Case Law, online: INPLP
Nursiyono, J. A., & Huda, Q. (2023). Analisis Sentimen Twitter Terhadap Perlindungan Data Pribadi Dengan Pendekatan Machine Learning. Jurnal Pertahanan & Bela Negara, 13(1), 1-16.
Putra, C. A. G., Budiartha, I. N. P., & Ujianti, N. M. P. (2023). Perlindungan Hukum Terhadap Konsumen dalam Persfektif Kesadaran Hukum Masyarakat. Jurnal Konstruksi Hukum, 4(1), 13-19.
Saputra, R. D., Rachim, K. V., & Taniady, V. (2023). Empowering Voices: Building an Electronic Petition System for Strengthening Freedom of Speech in Indonesia. Journal of Judicial Review, 25(1), 71-88.
Situmeang, S. M. T. (2021). Penyalahgunaan Data Pribadi Sebagai Bentuk Kejahatan Sempurna Dalam Perspektif Hukum Siber. Sasi, 27(1), 38-52.
Tektona, R. I. (2023). Kepastian Hukum Pemilik Data Pribadi Dalam Aplikasi Satu Sehat. Jurnal Legislasi Indonesia, 20(1), 28-41.
Treacy, B. (2017). Working Party Confirms ‘controller ‘and ‘processor ‘distinction. Privacy and Data Protection, 8(8), 3-5.
Tsamara, N. (2021). Perbandingan Aturan Perlindungan Privasi Atas Data Pribadi Antara Indonesia Dengan Beberapa Negara. Jurnal Suara Hukum, 3(1), 53-84.
Van Alsenoy, B. (2016). Liability under EU data protection law: from Directive 95/46 to the General Data Protection Regulation. J. Intell. Prop. Info. Tech. & Elec. Com. L., 7, 271.
Wijaya, I. P. A. D., & Purwanto, I. W. N. (2019). Perlindungan Hukum Dan Tanggung Jawab Para Pihak Dalam Transaksi Bisnis Elektronik Di Indonesia. Kertha Negara, 7(10), 1-16.







Most read articles by the same author(s)