Legal Protection of Bank Rakyat Indonesia Customers Against Personal Data Breaches under Law No. 27 of 2022 and Law No. 1 of 2024

Authors

  • Azzahrah Munirah Kesuma Study Program of Law, Faculty of Law, Bandung Islamic University, Indonesia
  • Muhammad Ilman Abidin Study Program of Law, Faculty of Law, Bandung Islamic University, Indonesia

Keywords:

legal protection, personal data protection, banking customers

Abstract

Abstract. The banking sector holds a strategic position as a financial intermediary supporting national economic development. The rapid growth of digital banking services driven by information technology aims to enhance convenience and efficiency for customers. In providing such services, banks are legally obligated to protect customers by safeguarding the confidentiality of personal data in accordance with the confidentiality principle stipulated in Article 40 of Law Number 10 of 1998 on Banking. Personal data protection is further strengthened under Law Number 27 of 2022 on Personal Data Protection and Article 15 paragraph (2) of Law Number 1 of 2024 on Electronic Information and Transactions, which imposes responsibility on Electronic System Operators. In practice, personal data breaches involving customers of Bank Rakyat Indonesia (Bank BRI) have resulted in financial losses. This article examines the legal protection afforded to Bank BRI customers whose personal data have been compromised and analyzes the bank’s liability for such incidents. This study employs a normative juridical research method based on library research. The findings show that customer protection is implemented through preventive and repressive legal measures, while Bank BRI’s liability arises from its obligations as a Personal Data Controller and an Electronic System Operator

References

Efrianto, L. B. P., & Diana Wiyanti. (2022). Tanggung Jawab Bank Terhadap Nasabah yang Dananya Terbukti Digunakan oleh Karyawan Bank. Jurnal Riset Ilmu Hukum, 107–112. https://doi.org/10.29313/jrih.v2i2.1457

Fadilla, M. F., & Nurcahyono, A. (2023). Kajian Kriminologi terhadap Penyebaran Data Pribadi yang Dilakukan oleh Peretas (Hacker) Dihubungkan dengan Undang-Undang Nomor 27 Tahun 2022 Tentang Perlindungan Data Pribadi. https://journal.sbpublisher.com/index.php/lol

Ririn Puspita Dewi, & Diana Wiyanti. (2024). Perlindungan Hukum Nasabah atas Peretasan Data Pribadi ditinjau dari Undang Undang. Jurnal Riset Ilmu Hukum, 95–100. https://doi.org/10.29313/jrih.v4i2.5193

Djumhana, M. Banking Law in Indonesia. Citra Aditya Bakti, Bandung, 2006.

Fuady, Munir. Banking Law. Citra Aditya Bakti, Bandung, 1999.

Hadjon, Philipus M. Introduction to Indonesian Administrative Law. Gadjah Mada University Press, Yogyakarta, 2011.

Law Number 1 of 2024 concerning the Second Amendment to Law Number 11 of 2008 concerning Information and Electronic Transactions.

Law Number 8 of 1999 concerning Consumer Protection.

Law Number 10 of 1998 concerning Banking.

Law Number 11 of 2008 concerning Information and Electronic Transactions.

Law Number 27 of 2022 concerning Personal Data Protection.

Marlina, A., & Bimo, W. A. “Bank Digitalization to Improve Service and Customer Satisfaction.” Innovator, Vol. 7, No. 1, 2018, pp. 14–34.

Soekanto, Soerjono. Normative Law Research: A Brief Overview. PT Raja Grafindo Persada, Jakarta, 2009.

The 1945 Constitution of the Republic of Indonesia.

Usanti, Trisadini P., & Somad, Abd. Banking Law. Kencana, Surabaya, 2017.

Downloads

Published

2026-02-02