A Static Analysis of Privacy by Design Compliance in Indonesian Quick-Service Restaurant Applications

Authors

  • Emanuel Ristian Handoyo Sistem Informasi, Fakultas Teknologi Industri, Universitas Atma Jaya Yogyakarta, Yogyakarta, Indonesia
  • Flourensia Sapty Rahayu Sistem Informasi, Fakultas Teknologi Industri, Universitas Atma Jaya Yogyakarta, Yogyakarta, Indonesia

DOI:

https://doi.org/10.36080/idealis.v9i2.3825

Keywords:

Android privacy, Privacy by Design, Personal Data Protection Law (UU PDP), Static Analysis, QSR applications

Abstract

The adoption of Quick-Service Restaurant (QSR) apps in Indonesia tripled from 2020 to the following three years. However, technical privacy audits of local apps remain very limited, and no research has systematically evaluated QSR apps in Indonesia using technical methods. To address this gap as the study's objective, the privacy compliance of QSR applications was systematically evaluated. Methodologically, the PbD-MASVS-MobSF evaluation framework was implemented, wherein Privacy by Design (PbD) principles, OWASP MASVS privacy controls, and Mobile Security Framework (MobSF) processes were integrated. As a sample, seven QSR apps were analysed, and their privacy findings were compared to the provisions of Law No. 27 of 2022 on Personal Data Protection (UU PDP). Regarding the key results, it was found that the apps were at a MEDIUM to HIGH risk level, with MobSF scores of 39-54 out of 100. The compliance analysis found that the apps consistently failed to meet six of the ten MobSF subprocesses. Meanwhile, strong compliance was only identified in the absence of API access for device identification. These findings indicate that privacy risks in the Indonesian QSR sector are structural and sectoral. Crucially, because only static analysis was utilised in this assessment, the findings are considered indicative rather than conclusive, and legal non-compliance with the PDP Law cannot be independently established. As a primary contribution, an operational framework that connects static analysis results, privacy design principles, and national regulatory requirements is provided as a reference for application developers, privacy auditors, and regulators.

Downloads

Download data is not yet available.

References

[1] Asosiasi Penyelenggara Jasa Internet Indonesia (APJII), “PROFIL INTERNET INDONESIA 2026: Survei Penetrasi Internet dan Perilaku Penggunaan Internet,” 2026. Accessed: Jun. 14, 2026. [Online]. Available: https://survei.apjii.or.id/survei/group/12

[2] D. E. Mahameru, A. Nurhalizah, H. Badjeber, A. Wildan, and H. Rahmadia, “Implementasi UU Perlindungan Data Pribadi Terhadap Keamanan Informasi Identitas di Indonesia,” Esensi Hukum, vol. 5, no. 2, pp. 115–131, 2024, doi: 10.35586/esensihukum.v5i2.240.

[3] S. Kemp, “Digital 2026 Mid-Year Global Update Report,” Apr. 2026. Accessed: May 30, 2026. [Online]. Available: https://datareportal.com/reports/digital-2026-mid-year-global-update-report

[4] S. Kemp, “Digital 2026: Indonesia — DataReportal – Global Digital Insights,” Nov. 2026. Accessed: Jun. 14, 2026. [Online]. Available: https://datareportal.com/reports/digital-2026-indonesia

[5] E. Lee, J. Kim, J. Kim, and C. Koo, “Information Privacy Behaviors during the COVID-19 Pandemic: Focusing on the Restaurant Context,” Information Systems Frontiers, vol. 25, no. 5, pp. 1829–1845, 2023, doi: 10.1007/s10796-022-10321-1.

[6] J. Sutrisno, A. Tarigan, and I. D. C. Purnomo, “Understanding the role of gamification and loyalty programs in restaurant apps: a systematic literature review and conceptual framework development,” Journal of Business & Applied Management, vol. 19, no. 1, 2026, doi: 10.30813/jbam.v19i1.9775.

[7] U. D. Amama, F. Talgatuly, A. F. Kolawole, and O. Oluwatobi, “Data Engineering and Privacy Challenges in Loyalty Card Programs: Insights from Retail, Banking, and Hospitality,” Asian Journal of Advanced Research and Reports, vol. 18, no. 11, pp. 340–357, 2024, doi: 10.9734/ajarr/2024/v18i11800.

[8] J. Singh, “Bugs in a major McDonald’s India delivery system exposed sensitive customer data | TechCrunch,” TechCrunch Media LLC. Accessed: May 31, 2026. [Online]. Available: https://techcrunch.com/2024/12/19/bugs-in-a-major-mcdonalds-india-delivery-system-exposed-sensitive-customer-data/

[9] L. Abrams, “Domino’s India discloses data breach after hackers sell data online,” Bleeping Computer® LLC. Accessed: May 31, 2026. [Online]. Available: https://www.bleepingcomputer.com/news/security/dominos-india-discloses-data-breach-after-hackers-sell-data-online/

[10] Y. Yokotani, A. C. Kurnia, W. Wirazilmustaan, and R. D. Salfutra, “Pengendalian Data Pribadi Dan Ruang Siber Oleh Platform Digital Big Data Global Terkait Kedaulatan Digital Indonesia,” PROGRESIF: Jurnal Hukum, vol. 19, no. 1, pp. 70–80, 2025, doi: 10.33019/cdt5p455.

[11] K. Kollnig et al., “Before and after GDPR: tracking in mobile apps,” Internet Policy Review, vol. 10, no. 4, 2021, doi: 10.14763/2021.4.1611.

[12] Z. R. Alkindi, M. Sarrab, and N. Alzeidi, “User Privacy and Data Flow Control for Android Apps: Systematic Literature Review,” Journal of Cyber Security and Mobility, 2021, doi: 10.13052/jcsm2245-1439.1019.

[13] A. Abraham, “AppSec PNW: Android and iOS Application Security with MobSF,” 2024. Accessed: May 30, 2026. [Online]. Available: https://mobsf.github.io/Mobile-Security-Framework-MobSF/presentations.html

[14] “OWASP MASVS - OWASP Mobile Application Security.” Accessed: May 31, 2026. [Online]. Available: https://mas.owasp.org/MASVS/

[15] R. A. Faozi, N. W. A. Majid, and S. Widodo, “Security Maturity Assessment of Indonesian Android Mobile Banking Apps using MobSF and OWASP,” Edumatic: Jurnal Pendidikan Informatika, vol. 10, no. 1, pp. 80–89, Mar. 2026, doi: 10.29408/edumatic.v10i1.33285.

[16] U. Kishnani and S. Das, “Security and Privacy Assessment of U.S. and Non-U.S. Android E-Commerce Applications,” in Springer, 2026, pp. 444–454. doi: 10.1007/978-3-032-13714-2_27.

[17] S. A. Khan et al., “An Android Applications Vulnerability Analysis Using MobSF,” in Proceedings - 2024 International Conference on Engineering and Computing, ICECT 2024, Institute of Electrical and Electronics Engineers Inc., 2024. doi: 10.1109/ICECT61618.2024.10581312.

[18] J. Zhu, K. Li, S. Chen, L. Fan, J. Wang, and X. Xie, “A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android,” IEEE Transactions on Software Engineering, vol. 50, no. 12, pp. 3385–3402, 2024, doi: 10.1109/TSE.2024.3488041.

[19] P. Nur Izzati and K. Kasmawi, “Static Analysis-Based Security Enhancement for Mobile Applications Using Mobile Security Framework (MOBSF),” Journal of Applied Informatics and Computing, vol. 9, no. 4, pp. 1272–1279, 2025, doi: 10.30871/jaic.v9i4.9525.

[20] A. Cavoukian, “Privacy by design: the definitive workshop. A foreword by Ann Cavoukian, Ph.D,” Identity in the Information Society, vol. 3, no. 2, pp. 247–251, 2010, doi: 10.1007/s12394-010-0062-y.

[21] V. C. Andrade, R. D. Gomes, S. Reinehr, C. O. D. A. Freitas, and A. Malucelli, “Privacy by Design and Software Engineering,” in Proceedings of the XXI Brazilian Symposium on Software Quality, New York, NY, USA: ACM, Nov. 2022, pp. 1–10. doi: 10.1145/3571473.3571480.

[22] S. A. de Chaves and F. Barreto Vavassori Benitti, “Privacy by Design in Software Engineering: An update of a Systematic Mapping Study,” in Proceedings of the 38th ACM/SIGAPP Symposium on Applied Computing, New York, NY, USA: ACM, Mar. 2023, pp. 1362–1369. doi: 10.1145/3555776.3577626.

[23] C. Del-Real, E. De Busser, and B. van den Berg, “A systematic literature review of security and privacy by design principles, norms, and strategies for digital technologies,” International Review of Law, Computers & Technology, vol. 39, no. 3, pp. 374–405, 2025, doi: 10.1080/13600869.2025.2457227.

[24] M. Hatamian, S. Wairimu, N. Momen, and L. Fritsch, “A privacy and security analysis of early-deployed COVID-19 contact tracing Android apps,” Empir. Softw. Eng., vol. 26, no. 3, p. 36, 2021, doi: 10.1007/s10664-020-09934-4.

[25] A. E. Waldman, “Data Protection by Design? A Critique of Article 25 of the GDPR,” Yale Journal of Law & Technology, 2021, [Online]. Available: https://ssrn.com/abstract=3773143

[26] R. Alt, “Digital Transformation in the Restaurant Industry: Current Developments and Implications,” Journal of Smart Tourism, vol. 1, no. 1, pp. 69–74, 2021, doi: 10.52255/smarttourism.2021.1.1.9.

[27] T. Sze and G. Gunasekara, “A Privacy Trojan Horse? Consumer Loyalty Programmes in the Grocery Sector and Data Privacy,” SSRN Electronic Journal, 2025, doi: 10.2139/ssrn.5628590.

[28] E. Blancaflor, I. Z. L. Delfin, A. Molate, A. I. Penafiel, A. Villaluz, and A. K. Balan, “Ethical Use of Geolocation Data: Privacy Concerns in Food Delivery Applications in the Philippines,” in Proceedings of the 2024 7th International Conference on Information Management and Management Science, New York, NY, USA: ACM, Aug. 2024, pp. 346–353. doi: 10.1145/3695652.3695683.

[29] C. Mulligan, G. Gillis, L. Remedios, C. Parsons, L. Vergeer, and M. Potvin Kent, “Children’s digital privacy on fast-food and dine-in restaurant mobile applications,” PLOS Digital Health, vol. 4, no. 2, p. e0000723, 2025, doi: 10.1371/journal.pdig.0000723.

[30] Z. Q. Ferdyan Putri and Y. Efawati, “Exploring the Impact of Customer Data Security on Consumer Trust in Gojek’s Digital Services,” International Journal Administration, Business & Organization, vol. 6, no. 1, pp. 136–145, 2025, doi: 10.61242/ijabo.25.332.

[31] A. R. Fadillah and A. Primajaya, “Analisis Keamanan Aplikasi Cafe Berbasis Android Menggunakan Mobile Security Framework (MobSF),” Jurnal Ilmiah Wahana Pendidikan, 2026, [Online]. Available: http://www.jurnal.peneliti.net/index.php/JIWP/article/view/12754

[32] S. Koch, M. Karl, R. Kirchner, M. Wessels, A. Paschke, and M. Johns, “The Impact of Default Mobile SDK Usage on Privacy and Data Protection,” Proceedings on Privacy Enhancing Technologies, vol. 2025, no. 1, pp. 808–823, 2025, doi: 10.56553/popets-2025-0042.

[33] M. Khedkar, A. Kumar Mondal, and E. Bodden, “A study of privacy-related data collected by Android apps,” Automated Software Engineering, vol. 33, no. 2, p. 45, 2026, doi: 10.1007/s10515-025-00589-3.

[34] Republik Indonesia, Undang-Undang Republik Indonesia Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi. Indonesia, 2022.

[35] F. Albirra, M. J. Soesapto, L. Agata, A. M. Pribadi, Istijanto, and Lydia Apriliani, “The Factors Influencing Online Food Delivery Usage Intention on Semi-Endemic Period,” TIJAB (The International Journal of Applied Business), vol. 7, no. 2, pp. 134–151, 2023, doi: 10.20473/tijab.v7.I2.2023.44104.

[36] D. S. Guaman, J. M. Del Alamo, and J. C. Caiza, “GDPR Compliance Assessment for Cross-Border Personal Data Transfers in Android Apps,” IEEE Access, vol. 9, pp. 15961–15982, 2021, doi: 10.1109/ACCESS.2021.3053130.

[37] D. S. Guamán, D. Rodriguez, J. M. del Alamo, and J. Such, “Automated GDPR compliance assessment for cross-border personal data transfers in android applications,” Comput. Secur., vol. 130, p. 103262, 2023, doi: 10.1016/j.cose.2023.103262.

[38] T. Fedynyshyn, O. Mykhaylova, and I. Opirskyy, “Security Implications of Mobile Development Frameworks: Findings from Static Analysis of Android Apps,” in 2024 IEEE 17th International Conference on Advanced Trends in Radioelectronics, Telecommunications and Computer Engineering (TCSET), IEEE, Oct. 2024, pp. 444–448. doi: 10.1109/TCSET64720.2024.10755684.

[39] C. Tila, “Leading Official Restaurant Apps in Indonesia in 2023, by Downloads (in 1,000s),” Apr. 2024. [Online]. Available: https://www.statista.com/statistics/1461199/indonesia-leading-official-restaurant-apps-by-downloads/

[40] V. Kouliaridis, G. Karopoulos, and G. Kambourakis, “Assessing the Security and Privacy of Android Official ID Wallet Apps,” Information, vol. 14, no. 8, p. 457, 2023, doi: 10.3390/info14080457.

Downloads

Published

07/31/2026

How to Cite

[1]
E. R. Handoyo and F. S. Rahayu, “A Static Analysis of Privacy by Design Compliance in Indonesian Quick-Service Restaurant Applications”, IDEALIS, vol. 9, no. 2, pp. 302–313, Jul. 2026.