Authors

  • Reza Eka Putra Universitas Jember, Jember, Indonesia Author

Keywords:

Accountability, Consumer Protection, Data Breach, Personal Data Protection, Public Digital Services, Regulatory Implementation

Abstract

The rapid expansion of digital technology has intensified the collection and processing of personal data in public services, including healthcare systems such as BPJS Kesehatan. This development increases efficiency but also exposes individuals to significant risks, particularly data breaches and privacy violations. This study examines the implementation of Law Number 27 of 2022 on Personal Data Protection in addressing data breach incidents and protecting users as data subjects, while also assessing the importance of evaluating regulatory implementation for consumer protection and accountability in public digital services. Using a qualitative normative legal approach, this research applies statute, case, and conceptual analyses based on secondary data, including legal documents and reports on the BPJS data breach. The findings reveal a substantial gap between normative legal provisions and practical enforcement. Although the law establishes comprehensive principles such as privacy, consent, and accountability, its implementation remains limited, particularly in ensuring data security, breach response, and access to remedies for affected users. The study further highlights that weak enforcement mechanisms and unclear accountability structures undermine consumer protection and public trust. Therefore, evaluating regulatory implementation is essential to identify compliance gaps, strengthen governance frameworks, and ensure the effective protection of personal data in digital public services.

Downloads

Published

2024-06-30