Aug 2026· Journal of Data Protection & Privacy· Vol 9, pp. 69· 0 citations
Abstract
This paper examines Indonesia’s legal framework for cross-border transfer of genomic data and evaluates how it balances the rights of data subjects, state sovereignty, and national security. Using a normative juridical method supported by comparative analysis, it reviews the Personal Data Protection Law 2022 and the Health Law 2023, along with their derivative ministerial regulations, in relation to international standards such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the World Health Organization (WHO) 2024 Guidelines, and China’s Regulation on Human Genetic Resources (HGR Regulation) 2019. The findings reveal three regulatory weaknesses: the limited recognition and protection of genomic data as sensitive data; the absence of benefit sharing and informed consent as fundamental rights of data subjects; and the lack of binding interstate treaty obligations to protect genomic data outside Indonesia. The paper proposes a ‘treaty-first’ approach in the Material Transfer Agreement (MTA), benefiting data subjects as a right, and a binding international framework designed explicitly for the cross-border protection of genomic data. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Bangladesh has entered a transformative phase in its digital governance journey with the enactment of the Personal Data Protection Act, 2026, which evolved from the Personal Data Protection Ordinance, 2025, and its subsequent amendment in February 2026. Current research is a comprehensive analysis of Bangladesh's data protection framework, examining its legislative evolution, key statutory provisions, institutional architecture, and implementation challenges. Based on comparative analysis with the European Union's General Data Protection Regulation (GDPR), documented breach incidents involving Bangladesh's National Identity database and private-sector data-fiduciaries, and scholarly and civil-society critiques, the study explores significant structural concerns including regulatory independence, state surveillance risk, and the balance between individual rights and state prerogatives. While the Act is a historic shift by recognizing citizens' personal data as their own property, substantial gaps exist between legislative text and effective implementation, in the absence of a mandatory breach-notification duty to affected individuals and Prime Minister's Office as the enforcing Authority. Strengthening Bangladesh's data protection framework through enhanced institutional independence, and transparent safeguards on state exemptions will offer closer alignment with international human-rights standards.
Mafruza Sultana, Md. Sobhan Ali· Legal Research & Analysi...· 0 citations
The Digital Personal Data Protection Act, 2023 establishes India’s first comprehensive framework for safeguarding digital personal data. By 2027, 900 million Indians are expected to utilize the Internet, making the Data Protection Act essential. The Digital Personal Data Protection (DPDP) Act, 2023 aiming to regulate the processing of personal data while balancing individual rights and business interests. This research paper critically examines the Act’s key provisions, including its definitions of personal data, obligations of data fiduciaries, rights of data principals and enforcement mechanism. The study also explores the Act’s impact on privacy rights as recognized under Article 21 of the Indian Constitution, its implications for Government surveillance and its potential efforts on cross border data transfers. The Act also establishes the Data Protection Board of India (DPBI) as regulatory body for monitoring compliance and resolving disputes. This paper the absence of an independent Data Protection Board with sufficient autonomy is critically evaluated. The DPDP Act and the laws that followed it provide a hopeful framework for a future in which technology supports humankind rather than subjugates it. The Government must uphold commitment to keeping the internet safe place citizens as the role of the internet in sustainable economic growth expands daily.
Dr.Brahmananda Sahoo· International Journal of Lat...· 0 citations
This article examines the normative construction of Article 56 of Law Number 27 of 2022 on Personal Data Protection, which regulates the requirements for cross-border personal data transfers. The study is motivated by the increasing transfer of personal data within the digital ecosystem, which may weaken the protection of data subjects’ rights if it is not supported by clear legal norms. This study aims to analyze the normative construction of Article 56 and the implications of its normative ambiguity for legal certainty and the legal protection of data subjects. This study employs a normative legal research method using statutory, conceptual, and limited comparative approaches. The findings show that Article 56 establishes three requirements for cross-border personal data transfers, namely an equivalent or higher level of protection, adequate and binding protection, and the consent of the data subject as a last resort. However, this provision does not yet provide clear normative parameters regarding the standard of equivalent protection, the form of adequate and binding safeguards, or the limits on the use of consent. Therefore, Article 56 needs to be clarified in order to provide legal certainty and ensure the protection of data subjects’ rights in cross-border personal data transfers.
Diana Puji Ratna Kusuma Fitri, H. Widodo, B. Hermono· Journal of Law, Politic and...· 0 citations
The present study aims to compare the Brazilian data protection framework, represented by the General Data Protection Law (LGPD), Law No. 13,709/2018, and the European system established by the General Data Protection Regulation (GDPR), identifying similarities, differences, and their current regulatory context. It is based on the premise that data protection has become a central issue in contemporary societies, marked by the intense digitalization of social, economic, and political relations, in which the large-scale processing of personal data plays a structural role. In this scenario, the establishment of standards of security, transparency, and informational integrity becomes essential for safeguarding fundamental rights, especially privacy and intimacy. Furthermore, the regulation of activities carried out by entities that collect and process data must be balanced, so as not to hinder technological innovation while ensuring adequate legal safeguards. The study examines the principles, foundations, and mechanisms provided by the LGPD and the GDPR, seeking to understand their points of convergence and divergence, as well as their impacts on the effectiveness of data protection. To this end, a deductive method is adopted, with a qualitative approach, based on bibliographic and documentary review of academic literature and legal frameworks. Finally, the research contributes to the legal debate on the development of regulatory models capable of addressing the challenges of a globalized and asymmetric digital environment, highlighting the role of regulatory authorities and data governance in promoting legal certainty and effective protection of data subjects in contemporary technological contexts..
Gean Medrado dos Santos, Bruno Freitas Ferreira, Leandro Borges Almeida et al.· ARACÊ· 0 citations
The transformation of personal information into strategic commodities within digital ecosystems has elevated data quality governance beyond mere administrative concerns to a constitutional imperative. This study examines the juridical construction of the accuracy principle within Indonesia's Law Number 27 of 2022 on Personal Data Protection (PDP Law) and contrasts this with Singapore's Personal Data Protection Act 2012 (PDPA). Using normative-comparative legal research enriched with statutory, conceptual, and comparative functionalism approaches, this research evaluates whether Indonesia's regulatory framework provides sufficient operational certainty for data controllers and adequate protection for data subjects. The analysis reveals that while Article 16 of the PDP Law nominally mandates accuracy, completeness, and consistency, the provision remains declarative and lacks definitional precision, temporal updating mechanisms, and clear liability parameters. Conversely, Singapore's PDPA operationalizes accuracy through the Accuracy Obligation and Correction Obligation, enforced by an independent Personal Data Protection Commission (PDPC) with investigative and sanctioning powers. This study proposes a juridical reconstruction of Indonesia's accuracy principle through periodic data audits, effective correction protocols, risk-based governance calibration, and the establishment of an independent supervisory authority with quasi-judicial competencies.
Seroja Rizki Amelia, S. Wiraguna· Journal of Law, Politic and...· 0 citations
In the context of digitalization of healthcare and the growth of cross-border mobility of patients, the protection of personal medical data in international health insurance systems is becoming increasingly relevant. Leading international organizations such as WHO, OECD, and the European Union are developing global standards for digital healthcare management based on the principles of confidentiality, transparency, and legal compatibility. The purpose of the study is to identify international legal mechanisms for protecting patients’ medical data in cross-border insurance and to propose ways to adapt them to the legislation of Kazakhstan. The methodological framework includes comparative legal, institutional, and system-structural approaches. The empirical basis was formed by an analysis of key documents: supranational (GDPR, Council of Europe Convention No. 108+, EHDS draft) and Kazakhstani (Law “On Personal Data and their Protection”, Code “On Public Health and the Healthcare System”). The implementation of the provisions of Conventions No. 108+ and GDPR into national legislation, the creation of a separate supervisory authority for the circulation of medical personal information, as well as the conclusion of agreements on mutual recognition of medical information security standards within the EAEU are proposed as priority areas for legal modernization. The implementation of these measures will allow Kazakhstan to bring domestic law in line with international obligations and strengthen the regulatory framework for digital healthcare.
N. T. Sultanova, Zh.T. Sairambaeva, P. Šustek· Eurasian Scientific Journal...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.