Examining Indonesian Government Accountability And Mitigation Measures In The 2024 Taxpayer Identification Number Data Breach

  • Alatas H
  • Djajaputra G
N/ACitations
Citations of this article
12Readers
Mendeley users who have this article in their library.

Abstract

This study examines the Indonesian government’s accountability for the 2024 Taxpayer Identification Number (NPWP) data breach and evaluates the implementation of personal data protection obligations under the Personal Data Protection Law (PDP Law). Using a normative legal research method with statutory, conceptual, and case-based approaches, the study finds that the Directorate General of Taxes (DGT) has not fully met its duties as a Personal Data Controller. The large-scale breach, involving more than six million records, reveals weaknesses in access control, Data Protection Impact Assessments (DPIAs), privacy-by-design practices, and breach notification procedures. The PDP Law provides administrative, civil, and criminal liability mechanisms for negligent actors, all of which may be applied cumulatively. The findings indicate a significant gap between legal norms and administrative practice, undermining public trust and limiting the effectiveness of the PDP Law in safeguarding personal data.

Cite

CITATION STYLE

APA

Alatas, H. H. R. A., & Djajaputra, G. (2025). Examining Indonesian Government Accountability And Mitigation Measures In The 2024 Taxpayer Identification Number Data Breach. JIHK, 7(2), 1234–1248. https://doi.org/10.46924/jihk.v7i2.385

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free