TY - GEN
T1 - Privacy Patterns and Objectives for Legally Compliant Software Based on the Indonesia's PDP Law
AU - Herwanto, Guntur Budi
AU - Nurwidyantoro, Arif
AU - Ningtyas, Annisa Maulida
AU - Nurfajri, Muhammad Oriza
AU - Quirchmayr, Gerald
AU - Tjoa, A. Min
PY - 2025/12/3
Y1 - 2025/12/3
N2 - Organizations worldwide face significant challenges in translating privacy regulations into implementable technical requirements, creating a critical gap between legal privacy compliance and system development. This paper adapts KORA (Konkretisierung Rechtlicher Anforderungen - Concretization of Legal Requirements) methodology by incorporating established privacy patterns to systematically translate regulatory privacy requirements into applicable solutions. Applying this methodology, we examine Indonesia's Personal Data Protection Law (UU-PDP) to propose technical solutions for privacy compliance. Our three-phase methodology systematically identifies regulatory requirements, maps them to established privacy objectives, including transparency, manageability, and intervenability, and connects them to implementable privacy patterns. Through rigorous analysis of the 76 articles in the UU-PDP, we extracted 183 distinct legal criteria in 59 articles, revealing that transparency, manageability, and intervenability emerge as predominant regulatory priorities. Our analysis identifies 53 applicable privacy patterns, with the implementation of just 10 key patterns addressing half of the regulatory requirements, providing an efficient pathway toward compliance for resource-constrained organizations. The research contributes a privacy-oriented regulatory engineering framework and empirical evidence that structured approaches can achieve substantial compliance coverage through targeted technical implementations.
AB - Organizations worldwide face significant challenges in translating privacy regulations into implementable technical requirements, creating a critical gap between legal privacy compliance and system development. This paper adapts KORA (Konkretisierung Rechtlicher Anforderungen - Concretization of Legal Requirements) methodology by incorporating established privacy patterns to systematically translate regulatory privacy requirements into applicable solutions. Applying this methodology, we examine Indonesia's Personal Data Protection Law (UU-PDP) to propose technical solutions for privacy compliance. Our three-phase methodology systematically identifies regulatory requirements, maps them to established privacy objectives, including transparency, manageability, and intervenability, and connects them to implementable privacy patterns. Through rigorous analysis of the 76 articles in the UU-PDP, we extracted 183 distinct legal criteria in 59 articles, revealing that transparency, manageability, and intervenability emerge as predominant regulatory priorities. Our analysis identifies 53 applicable privacy patterns, with the implementation of just 10 key patterns addressing half of the regulatory requirements, providing an efficient pathway toward compliance for resource-constrained organizations. The research contributes a privacy-oriented regulatory engineering framework and empirical evidence that structured approaches can achieve substantial compliance coverage through targeted technical implementations.
U2 - 10.1007/978-3-032-11976-6_19
DO - 10.1007/978-3-032-11976-6_19
M3 - Contribution to proceedings
SN - 978-3-032-11975-9
T3 - Lecture Notes in Computer Science
SP - 266
EP - 281
BT - Information Integration and Web Intelligence
A2 - Pardede, Eric
A2 - Ma, Qiang
A2 - Kotsis, Gabriele
A2 - Amagasa, Toshiyuki
A2 - Nadamoto, Akiyo
A2 - Khalil, Ismail
PB - Springer Cham
CY - Cham
T2 - 27th International Conference on Information Integration and Web Intelligence, iiWAS 2025
Y2 - 8 December 2025 through 10 December 2025
ER -