Personal Data Security in Indonesia and Thailand Shaped by Digital Literacy and Law Enforcement

Created by AI

FORMOSA NEWS - Public trust in digital services is closely connected to how secure people believe their personal data is. A comparative study by Ar Rahiim Innash, Arista Candra Irawati, Vicentius Simon Suyanto, and Sudijono Sastroatmodjo of University Ngudi Waluyo, together with Prattana Srisuk of Thai Global Business Administration College, Thailand, published in 2026, found that public perceptions of personal data security in Indonesia and Thailand are influenced not only by the existence of data protection laws, but also by digital literacy, experiences with data breaches, service-provider transparency, and the consistency of law enforcement.

The findings are increasingly important as digital services become part of everyday life across Southeast Asia. In Indonesia, the Indonesian Internet Service Providers Association (APJII) reported 221.56 million internet users in 2024, representing an internet penetration rate of 79.5%. Thailand recorded approximately 63.21 million internet users at the beginning of 2024, with internet penetration reaching 88%. The expansion of digital services has also increased the amount of personal information collected and processed by e-commerce platforms, financial services, transportation applications, social media, and government systems.

Personal information handled by digital services can include names, addresses, telephone numbers, location data, transaction histories, consumption patterns, health information, and biometric data. For this reason, the authors argue that personal data security is no longer simply a technical issue. It has become a social, legal, economic, and governance concern that directly affects public confidence in the digital ecosystem.

Indonesia Faces a Major Trust Challenge

Indonesia has established Law No. 27 of 2022 on Personal Data Protection, commonly known as the PDP Law. The law came into force on October 17, 2022, with its transition period ending on October 17, 2024. It provides a comprehensive legal framework covering data-subject rights, obligations of data controllers and processors, personal data processing, cross-border data transfers, administrative and criminal sanctions, and other mechanisms for protecting personal information.

However, the existence of legislation does not automatically make people feel safe. The study found that public perceptions in Indonesia have been strongly influenced by reports of major data-security incidents. The cases discussed include cyberattacks involving PT Kereta Api Indonesia, disruptions to the General Elections Commission's Sirekap system, reported breaches involving Biznet and the National Civil Service Agency, the ransomware attack on the Temporary National Data Center (PDNS) 2 in Surabaya, and the alleged leakage of taxpayer identification data.

The PDNS 2 incident was particularly significant because its impact extended beyond private technology companies. The ransomware attack reportedly disrupted hundreds of government agencies and public services, including immigration and education services. The incident reinforced the perception that personal data protection is also a matter of government infrastructure security and public-sector governance.

Despite these concerns, Indonesians continue to depend heavily on digital services for payments, communication, employment, education, transportation, and government services. The authors relate this behavior to the concept of privacy calculus, in which users continue accepting certain privacy risks when they believe the benefits of digital services outweigh the potential harm.

Thailand Shows Stronger Regulatory Enforcement

Thailand has the Personal Data Protection Act B.E. 2562 (2019), commonly known as the PDPA. The law became fully effective on June 1, 2022. Thailand has also established the Personal Data Protection Committee (PDPC) and introduced the Personal Data Protection Master Plan 2024–2027 to strengthen compliance, public awareness, and data governance.

One of the clearest differences identified by the study is the visibility of regulatory enforcement. On July 31, 2024, Thai authorities imposed the first administrative fine under the PDPA, amounting to THB 7 million, against a data controller. The violations included failure to appoint a Data Protection Officer (DPO), inadequate security measures, and delayed notification of a personal data breach.

For the public, such enforcement can provide a visible signal that data-protection rules have real consequences. According to Innash and his co-authors, people evaluate data protection not only by asking whether laws exist, but also by observing whether regulators actively respond to violations and hold organizations accountable.

Thailand nevertheless continues to face data-security risks. The article discusses reports concerning the alleged sale of nearly 20 million Thai citizens' records and other incidents involving customer information. These cases show that stronger regulation does not eliminate cybersecurity threats, but visible enforcement may contribute to greater confidence that violations will be addressed.

Five Factors Shape Public Trust

The comparison between the two countries identifies five major factors that influence how people perceive personal data security.

  1. Digital literacy. Users with stronger digital skills are generally better able to understand application permissions, recognize suspicious links, manage passwords, use multi-factor authentication, and evaluate privacy policies.

  2. Experience with data breaches and fraud. Direct experience or exposure to phishing, telephone scams, fake notifications, and misuse of personal information can increase users' awareness and concern about privacy risks.

  3. Transparency from service providers. Users are more likely to trust platforms that clearly explain why personal data are collected and processed, provide meaningful privacy controls, and communicate security incidents promptly.

  4. Law enforcement. Concrete sanctions can demonstrate that organizations are accountable when they fail to protect personal information.

  5. Institutional reputation. Organizations repeatedly associated with security incidents may experience declining credibility and public confidence, even when users continue relying on their services because alternatives are limited.

These findings suggest that personal data protection cannot be assigned solely to individual users. Governments, regulators, businesses, and citizens all have responsibilities in building a secure digital ecosystem. The authors conclude that public trust is more likely to grow when regulations are consistently enforced, supervisory authorities operate effectively, digital service providers maintain transparency, and citizens possess adequate digital-security literacy.

How the Study Was Conducted

The article uses a qualitative comparative approach based on a literature review. The authors examined regulations, official reports, legal publications, digital sources, and reports concerning data-breach incidents in Indonesia and Thailand.

The analysis was conducted in four stages: identifying regulatory frameworks, mapping recent data-breach cases, examining factors that influence public perceptions, and comparing the two countries. The researchers strengthened the analysis by triangulating legal sources, digital statistics, and case reports from multiple independent sources.

Author Profiles

Ar Rahiim Innash — University Ngudi Waluyo.
Arista Candra Irawati — University Ngudi Waluyo.
Vicentius Simon Suyanto — University Ngudi Waluyo.
Sudijono Sastroatmodjo — University Ngudi Waluyo.
Prattana Srisuk — Thai Global Business Administration College, Thailand.

The source article does not provide the academic degrees or specific fields of expertise of each author, so these details are not added to avoid introducing unsupported information.

Research Source

Article Title: Public Perceptions of Personal Data Security in Digital Service Utilization in Indonesia and Thailand: A Comparative Analysis of Regulatory Frameworks, Risks, and User Trust
Journal: International Journal of Applied and Scientific Research (IJASR)
Volume: 4, No. 8
Year: 2026
Pages: 607–622
E-ISSN: 3025-7670

Posting Komentar

0 Komentar