Privacy Patterns and Objectives for Legally Compliant Software Based on the Indonesia’s PDP Law

Privacy Patterns and Objectives for Legally Compliant Software Based on the Indonesia’s PDP Law

Abstract

Organizations worldwide face significant challenges in translating privacy regulations into implementable technical requirements, creating a critical gap between legal privacy compliance and system development. This paper adapts KORA (Konkretisierung Rechtlicher Anforderungen - Concretization of Legal Requirements) methodology by incorporating established privacy patterns to systematically translate regulatory privacy requirements into applicable solutions. Applying this methodology, we examine Indonesia’s Personal Data Protection Law (UU-PDP) to propose technical solutions for privacy compliance. Our three-phase methodology systematically identifies regulatory requirements, maps them to established privacy objectives, including transparency, manageability, and intervenability, and connects them to implementable privacy patterns. Through rigorous analysis of the 76 articles in the UU-PDP, we extracted 183 distinct legal criteria in 59 articles, revealing that transparency, manageability, and intervenability emerge as predominant regulatory priorities. Our analysis identifies 53 applicable privacy patterns, with the implementation of just 10 key patterns addressing half of the regulatory requirements, providing an efficient pathway toward compliance for resource-constrained organizations. The research contributes a privacy-oriented regulatory engineering framework and empirical evidence that structured approaches can achieve substantial compliance coverage through targeted technical implementations.

Grafik Top
Authors
  • Herwanto, Guntur
  • Nurwidyantoro, Arif
  • Ningtyas, Annisa
  • Nurfajri, Muhammad
  • Quirchmayr, Gerald
  • Tjoa, A Min
Grafik Top
Shortfacts
Category
Paper in Conference Proceedings or in Workshop Proceedings (Paper)
Event Title
27th International Conference on Information Integration and Web Intelligence, iiWAS 2025
Divisions
Multimedia Information Systems
Security and Privacy
Subjects
Computersicherheit
Event Location
Matsue, Japan
Event Type
Conference
Event Dates
8-10 Dec 2025
Series Name
Information Integration and Web Intelligence
Publisher
Springer Nature Switzerland
Page Range
pp. 266-281
Date
3 December 2025
Export
Grafik Top