Privacy Statement
Privacy Statement
Dharmaputra Medical Law Journal (DMLJ)
Jurnal Dharmaputra Hukum Kesehatan
P-ISSN: 3124-1964 | E-ISSN: 3124-1840
Overview
The Dharmaputra Medical Law Journal (DMLJ) is committed to protecting the privacy of all individuals who interact with this journal — including authors, reviewers, readers, and any other users of the DMLJ website and OJS platform at https://dmedlaw.org.
This Privacy Statement explains what personal data DMLJ collects, why it is collected, how it is used, how it is stored, and the rights of individuals regarding their personal data. DMLJ is published by RSUD Wangaya, Denpasar, Bali, Indonesia, which acts as the data controller for personal data processed in connection with the journal.
Data Collected
DMLJ collects personal data that users provide directly when registering on the OJS platform, submitting manuscripts, or communicating with the editorial office. The categories of data collected include:
Identity Data
Full name, preferred name or title, and academic/professional credentials as provided during registration or submission.
Contact Data
Email address and, where provided, postal address and telephone number.
Affiliation Data
Institutional or organizational affiliation, department, country of residence or work.
Submission Metadata
Manuscript title, keywords, abstract, submission date, revision history, and editorial correspondence associated with a submission.
Technical Data
IP address, browser type, operating system, and session data collected automatically by the OJS platform for security and system administration purposes.
How Data is Used
Personal data collected by DMLJ is used exclusively for the following purposes:
- Editorial workflow: Managing the submission, peer review, revision, and publication process, including communication with authors, reviewers, and editors.
- Account administration: Creating and maintaining OJS user accounts and enabling users to access and use the submission system.
- Publication: Displaying author names, affiliations, and contact details (where applicable) in published articles in accordance with academic convention.
- Communication: Sending transactional communications related to submissions, peer review invitations, editorial decisions, and publication notifications.
- System security: Monitoring platform access for security and fraud prevention purposes.
No commercial use: DMLJ does not use personal data for marketing, advertising, or commercial profiling, and does not sell, rent, trade, or share personal data with any third party for commercial purposes.
OJS Platform & Data Storage
DMLJ uses the Open Journal Systems (OJS) platform, developed and maintained by the Public Knowledge Project (PKP). Personal data entered into the OJS platform is stored on servers managed by or on behalf of RSUD Wangaya. DMLJ takes reasonable technical and organizational measures to protect personal data from unauthorized access, loss, or disclosure.
No third-party sharing: Personal data is not shared with third-party organizations, commercial entities, or external services except as strictly necessary for the operation of the OJS platform and only under appropriate data processing agreements. DMLJ does not use third-party analytics, advertising networks, or social media tracking on its platform.
Legal Framework
UU PDP (Indonesia)
DMLJ operates in compliance with the Undang-Undang Perlindungan Data Pribadi (UU PDP), Undang-Undang Nomor 27 Tahun 2022, Indonesia's primary personal data protection law. RSUD Wangaya, as publisher, acts as the data controller under this law and is responsible for ensuring that personal data is processed lawfully, fairly, and in a manner that is transparent to the data subject.
GDPR Principles Adopted
DMLJ also adopts the core principles of the European Union's General Data Protection Regulation (GDPR) as best practice standards for data management, irrespective of the jurisdiction of individual users. These principles include: lawfulness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
Data Retention Policy
Personal data is retained for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. Specific retention practices include:
- Published articles: Author names and affiliations associated with published articles are retained indefinitely as part of the permanent scholarly record.
- Rejected manuscripts: Submission data and related correspondence for manuscripts that were not accepted are retained for a minimum of three years for editorial record-keeping and integrity purposes, then deleted unless a legal hold applies.
- Reviewer records: Reviewer identity and review activity records are retained for a minimum of five years to maintain the integrity of the peer review record.
- OJS account data: User account data is retained for as long as the account remains active. Users may request deletion of their account by contacting the editorial office.
Cookies
The DMLJ OJS platform uses session cookies to maintain user login state during an active session. These cookies are:
- Strictly necessary: Required for basic platform functionality (login, navigation between pages of the system).
- Session-based: These cookies expire when the browser session is closed and are not retained on the user's device beyond the active session.
- First-party only: DMLJ does not use third-party cookies, tracking scripts, advertising cookies, or cross-site tracking technologies of any kind.
No analytics or behavioral tracking is conducted through cookies on the DMLJ platform.
Your Rights Regarding Your Data
Authors, reviewers, and other registered users of the DMLJ platform have the following rights with respect to their personal data:
Right of Access
Request a copy of the personal data DMLJ holds about you.
Right of Rectification
Request correction of inaccurate or incomplete personal data.
Right of Erasure
Request deletion of personal data, subject to legal and archiving obligations.
Right to Object
Object to processing of your personal data in certain circumstances.
Right of Restriction
Request that the processing of your data be restricted in certain circumstances.
Right to Portability
Request a copy of your data in a structured, machine-readable format where technically feasible.
To exercise any of the above rights, or to submit a data-related inquiry, please contact the editorial office by email at udiana.krisna@gmail.com with the subject line: DATA REQUEST — [Your Name]. Requests will be acknowledged within 5 business days and responded to within 30 calendar days, in accordance with applicable law.
Principal Contact: Gede Krisna Udiana, S.K.M., M.H.Kes. | +62 812-3898-787 | udiana.krisna@gmail.com