Regulating Digital Privacy in Indonesia: The Practice of Data Subject Rights and Controller Duties in the FotoYu App
DOI:
https://doi.org/10.32332/istinbath.v22i02.11448Keywords:
Personal Data Protection, Personal Data Subject Rights, Personal Data Control Oblligation, FotoYuAbstract
The practice of personal data protection in artificial intelligence (AI)-based marketplace applications that utilize facial recognition technology (FRT) in Indonesia has not been comprehensively studied. This study analyzes the implementation of data subject rights and the fulfillment of data controller obligations by FotoYu under Law Number 27 of 2022 concerning Personal Data Protection (PDP Law). This study employs a normative juridical method, utilizing primary legal sources such as legislation, secondary sources including scholarly literature and doctrine, and tertiary materials as supporting references. The findings indicate that FotoYu and its Creators have not fully met the core obligations of data controllers, particularly regarding explicit consent, transparency, and effective data deletion mechanisms. Additional challenges arise from inaccurate FRT performance, limited regulatory frameworks on FRT and AI, the absence of implementing regulations for the PDP Law, and a lack of a dedicated data protection authority. This study contributes by providing a normative interpretation of PDP Law provisions in the context of AI-based FRT platforms and offers policy recommendations, including strengthening regulations specific to FRT and AI, accelerating PDP Law implementation regulations, and establishing an independent data protection authority to ensure effective oversight and law enforcement in Indonesia.
References
Adnasohn Aqilla Respati. “Reformulasi Undang-Undang ITE Terhadap Artificial Intelligence Dibandingkan Dengan Uni Eropa Dan China AI Act Regulation.” Jurnal USM Law Review 7, no. 3 (2024): 1737–58.
Agata Ramadhani, Syafira. “Komparasi Pengaturan Perlindungan Data Pribadi Di Indonesia Dan Uni Eropa Comparison of Personal Data Protection Regulation in Indonesia and the European Union.” Rewang Rencang : Jurnal Hukum Lex Generalis. 3, no. 1 (2022): 73–84. https://doi.org/10.56370/jhlg.v3i1.173.
Ali. “FH UNS-Mafindo Bahas Marketplace Fotografi, Pengguna Dan Fotografer FotoYu Harus Saling Melindungi.” Joglosemar News.Com, 2025. https://joglosemarnews.com/2025/03/fh-uns-mafindo-bahas-marketplace-fotografi-pengguna-dan-fotografer-fotoyu-harus-saling-melindungi/.
Athallah Rafidiansyah. “Hak Atas Potret Dalam Komersialisasi Pada Aplikasi FotoYu: Tinjauan Hak Cipta.” 2025.
Ati, M. “Big Data Security and Privacy Implementation: The Way Ahead.” Paper presented at 7th IEEE International Conference on Engineering Technologies and Applied Sciences, ICETAS 2020. 2020. https://doi.org/10.1109/ICETAS51660.2020.9484196.
Aulia Alayna Suvil, Firdaus Firdaus, M. Arif Ramadhan, Wanda Darma Putra, and Dwi Putri Lestarika. “Implementasi Perlindungan Data Pribadi Berdasarkan Undang-Undang Nomor 11 Tahun 2020.” Jurnal Hukum, Politik Dan Ilmu Sosial 3, no. 4 (2024): 70–80. https://doi.org/10.55606/jhpis.v3i4.4235.
Awwaliyah, Rizka Putri, and Sony Juniarti. “Perbandingan General Data Protection Regulation (GDPR) Dengan Regulasi Perlindungan Data Di Negara-Negara Asia Tenggara.” Jurnal Hukum Dan Kewarganegaraan 4, no. 4 (2024). https://doi.org/10.3783/causa.v4i4.3535.
Ayiliani, Fanisa Mayda, and Elfia Farida. “Urgensi Pembentukan Lembaga Pengawas Data Pribadi Sebagai Upaya Pelindungan Hukum Terhadap Transfer Data Pribadi Lintas Negara.” Jurnal Pembangunan Hukum Indonesia 6, no. 3 (2024): 431–55. https://doi.org/10.14710/jphi.v6i3.%25p.
Br Girsang, Sarimah Yemima. “Pentingnya Regulasi Khusus Sistem Face Recognition Technology Sebagai Produk Artificial Intelligence Dalam Peningkatan Keamanan Dan Penegakan Hukum Di Indonesia.” Nommensen Journal of Legal Opinion 05 (2024): 86–98. https://doi.org/10.51622/njlo.v5i2.1817.
Cahyadaru Kuncorojati. “133 Juta Serangan Siber Hantam Indonesia, Ancam Celah Keamanan Dan Botnet Iot.” Medcom.Id, 2025. https://www.medcom.id/teknologi/news-teknologi/5b2wOjnk-133-juta-serangan-siber-hantam-indonesia-ancam-celah-keamanan-dan-botnet-iot.
Djaja S. Meliala. Hukum Perdata Dalam Perspektif BW. Bandung: Nuansa Aulia, 2012.
Enggarsasi, U., N.K. Sa’diyah, and P.A. Martio. “LEGAL SAFEGUARDS FOR VICTIMS OF DATA DISSEMINATION CRIMES AND CYBERCRIME PROTECTION.” Jurnal Hukum Unissula 40, no. 2 (2024): 258–77. https://doi.org/10.26532/jh.v40i2.39974.
Fattah Rizki, Miyuki, and Abdul Salam. “Pertanggungjawaban Hukum Pengumpulan Data Biometrik Melalui Artificial Intelligence Tanpa Persetujuan Pemilik Data (Studi Kasus Clearview AI Inc. Di Yunani Dan Inggris).” Lex Patrimonium 2, no. 2 (2023): 1–16.
Fence M. Wantu. Pengantar Ilmu Hukum. Edited by UNG Press. Gorontalo, 2015.
Floubianca Viola. “Potensi Pelanggaran Hak Privasi Dalam Penggunaan Face Recognition Untuk Pengawasan Keamanan Di Ruang Publik.” Universitas Katolik Parahyangan, 2023.
FotoYu. “Cara Kerja FotoYu.” FotoYu. https://www.fotoyu.com/how-it-works.
Hasibuan, Edi Saputra, and Elfirda Ade Putri. “Perlindungan Keamanan Atas Data Pribadi Di Dunia Maya.” Jurnal Hukum Sasana 10, no. 1 (2024): 70–83. https://doi.org/10.31599/sasana.v10i1.2134.
Hisbulloh, M.H. “URGENSI RANCANGAN UNDANG-UNDANG (RUU) PERLINDUNGAN DATA PRIBADI.” Jurnal Hukum Unissula 37, no. 2 (2021): 119–33. https://doi.org/10.26532/jh.v37i2.16272.
Hoca, Y., D. Firat, and E. Çağlar. “Principles of Data Privacy and Security in a Cyber World.” In Handbook of Research on Cyber Law, Data Protection, and Privacy, 1–19. 2022. https://doi.org/10.4018/978-1-7998-8641-9.ch001.
Husna, Nur, Moh Nurman, and Yudhistira Nugroho. “Pembentukan Peraturan Pemerintah Tentang Face Recognition Technology Ditinjau Dari Undang-Undang Nomor 27 Tahun 2022 Tentang Perlindungan Data Pribadi.” Jurnal Ilmiah AKSES, no. 2 (2025): 1–6.
Kaczmarek, K., M. Karpiuk, and C. Melchior. “A Holistic Approach to Cybersecurity and Data Protection in the Age of Artificial Intelligence and Big Data.” Prawo i Wiez 50, no. 3 (2024): 103–21. https://doi.org/10.36128/PRIW.VI50.907.
Kementerian Komunikasi dan Digital. “Komitmen Pemerintah Melindungi Anak Di Ruang Digital.” Komdigi, 2025. https://www.komdigi.go.id/berita/artikel/detail/komitmen-pemerintah-melindungi-anak-di-ruang-digital.
Korengkeng, Michelle Lucia, Roy Ronny Lembong, and Feiby S. Wewengkang. “ANALISIS TINDAK PIDANA DEEPFAKE PORNOGRAFI DALAM PERSPEKTIF UNDANG-UNDANG INFORMASI DAN TRANSAKSI ELEKTRONIK.” Jurnal Fakultas Hukum UNSRAT 13, no. 3 (2025).
Mahameru, Danil Erlangga, Aisyah Nurhalizah, Ahmad Wildan, Mochamad Haikal, and Mohamad Haikal Rahmadia. “IMPLEMENTASI UU PERLINDUNGAN DATA PRIBADI TERHADAP KEAMANAN INFORMASI IDENTITAS DI INDONESIA.” Jurnal Esensi Hukum 5, no. 20 (2023): 115–31.
Nasakti, Ghazali Hasan. “IUS CONSTITUENDUM PENGGUNAAN TEKNOLOGI PENGENALAN WAJAH DALAM INDUSTRI DAN PENEGAKAN HUKUM DI INDONESIA.” Prosiding Konferensi Mahasiswa Nasional Ubaya Law Fair Tahun 2021, 2021.
Nawawi, J. “LEGAL PROTECTION OF PERSONAL DATA BASED ON REGULATION IN INDONESIA.” Jurnal Al-Dustur 5, no. 1 (2022): 96–106. https://doi.org/10.30863/jad.v5i1.2581.
Nayak, R., A. Jain, M. Saxena, and R. Kumar. “Cyber Security for Personal Data.” In Developing AI, IoT and Cloud Computing-Based Tools and Applications for Women’s Safety, 123–41. 2024. https://doi.org/10.1201/9781003538172-9.
Nufus, Hayatun, and Moh Soleh. “Tinjauan Yuridis Dalam Kasus Memotret Orang Tanpa Izin Untuk Kepentingan Komersial.” Jurnal Cakrawala Akademika 2, no. 1 (2025): 1–19. https://doi.org/10.70182/JCA.
Nurzihad, M.I., M. Ichsan, and F. Fitriyanti. “Personal Data Protection in Indonesian E-Commerce Platforms: The Maqasid Sharia Perspective.” 693 LNNS (2023): 1077–86. https://doi.org/10.1007/978-981-99-3243-6_88.
Pakpahan, Jonathan Matthew. “Kesadaran Urgensi Peran Pengendali Dan Prosesor Data Pribadi Dalam Rangka Pelindungan Data Pribadi Individu Berdasarkan Undang-Undang Nomor 27 Tahun 2022 Tentang Pelindungan Data Pribadi.” Jurnal Hukum To-Ra : Hukum Untuk Mengatur Dan Melindungi Masyarakat 10, no. 1 (2024): 119–37. https://doi.org/10.55809/tora.v10i1.331.
Puluhulawa, F.U., J. Puluhulawa, and M.G. Katili. “Legal Weak Protection of Personal Data in the 4.0 Industrial Revolution Era.” Jambura Law Review 2, no. 2 (2020): 182–200. https://doi.org/10.33756/jlr.v2i2.6847.
Rahmatullah, I. “FINANCIAL TECHNOLOGY AND THE LEGAL PROTECTION OF PERSONAL DATA: The Case of Malaysia and Indonesia.” Al-Risalah: Forum Kajian Hukum Dan Sosial Kemasyarakatan 20, no. 2 (2020): 197–214. https://doi.org/10.30631/alrisalah.v20i2.602.
Rambe, Rahmat, and Lukman Abdurrahman. “Implikasi Etika Dan Hukum Dalam Penggunaan Teknologi Pengenalan Wajah: Perlindungan Privasi Versus Keamanan Publik.” Jurnal Hukum Caraka Justitia 4, no. 2 (2024): 90–104. https://doi.org/10.30588/jhcj.v4i2.1828.
Rendreana, N.A., S. Cahyono, and R.A. Wijayanti. “Implementation of Gamification to Enhance Understanding of Personal Data Protection Based on Republic of Indonesia Law Number 27 of 2022.” 2023, 246–51. https://doi.org/10.1109/ICIMCIS60089.2023.10349080.
Rinjani, Muhamad Adri, and Ricky Firmansyah. “Hambatan Implementasi UU 27/2022 Dan Strategi Penguatan Perlindungan Data Pribadi Di Indonesia.” Jurnal Analisis Hukum 8, no. 1 (2025): 70–83. https://doi.org/10.38043/jah.v8i1.6793.
Rizal Amril Yahya. “Pudarnya Privasi Kita Di Hadapan Kamera Liar.” Tirto.Id, 2025. https://tirto.id/pudarnya-privasi-kita-di-hadapan-kamera-liar-hdcD#google_vignette.
Rumlus, Muhamad Hasan, and Hanif Hartadi. “Kebijakan Penanggulangan Pencurian Data Pribadi Dalam Media Elektronik.” Jurnal HAM 11, no. 2 (2020): 285. https://doi.org/10.30641/ham.2020.11.285-299.
Rusyda, Nabiha Khansa. “Perlindungan Hukum Erhadap Subjek Data Kebocoran Data Oleh Badan Publik Menurut UU Nomor 27 Tahun 2022.” Desentralisasi : Jurnal Hukum, Kebijakan Publik, Dan Pemerintahan 2, no. 3 (2025): 247–62. https://doi.org/10.62383/desentralisasi.v2i3.940.
Simatupang, Aldi Pebrian. Penerapan Algoritma Deep Learning Dalam Pengenalan Wajah Untuk Sistem Keamanan. 01 (2025): 7–12.
Soekanto, Soerjono. Kesadaran Hukum Dan Kepatuhan Hukum. Jakarta: CV. Rajawali, 1982.
Soerjono Soekanto. Penegakan Hukum. Jakarta: Bina Citra, 1983.
Tulay, M.A., and S. Olatunbosun. “Cybersecurity Techniques, Emerging Threats, and Industry Responses.” 2262 (2025): 336–53. https://doi.org/10.1007/978-3-031-85933-5_25.
Utama, F.S., D.E. Purwoleksono, and T. Rachman. “Data Leakage of the Indonesian Elections Commission in Legal Aspects of Personal Data Protection.” Media Iuris 7, no. 3 (2024): 479–98. https://doi.org/10.20473/mi.v7i3.55931.
Widjaja, Gunawan, and Fransiska Milenia Cesarianti. “Urgensi Pembentukan Lembaga Pengawas Pelindungan Data Pribadi Di Indonesia Berdasarkan Pasal 58 Juncto Pasal 59 Dan Pasal 60 Undang – Undang Nomor 27 Tahun 2022 Tentang Pelindungan Data Pribadi.” SINERGI : Jurnal Riset Ilmiah 1, no. 4 (2024): 234–42. https://doi.org/10.62335/8qf44b59.
Xanthidis, D., F. Alsuwaidi, M. Al Ali, A. Alolama, and M. Albaloushi. “Information Privacy and Emerging Technologies in the U.A.E.: Current Standing and Research Directions.” 2019, 314–18. https://doi.org/10.1109/ITT48889.2019.9075076.
Yeovandi, Felix, and Eko Prasetyo. “Evaluasi Keamanan Sistem Autentikasi Biometrik Pada Smartphone Dan Rekomendasi Implementasi Optimal.” JTIM : Jurnal Teknologi Informasi Dan Multimedia Evaluasi Keamanan Sistem Autentikasi Biometrik 7, no. 1 (2025): 133–48. https://doi.org/10.35746/jtim.v7i1.653.
Yopi Prayitno. “Pertanggungjawaban Perdata Perusahaan Nodeflux Atas Kerugian Pengguna Akibat Kesalahan Output Teknologi Artificial Intelligence (Face Recognition).” Universitas Sriwijaya, 2024.
Zorluoğlu Yilmaz, Ayça. “Joint Controllership Under the GDPR - Concept, Responsibilities, and Liability.” Juridical Tribune - Review of Comparative and International Law 15, no. 1 (2025): 93–107. https://doi.org/10.62768/TBJ/2025/15/1/06.
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Dwita Tarisa Putri

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.




