Bank Liability for Misuse of Customers Personal Data in Fictitious Credit Schemes

Authors

  • Ni Kadek Linda Warmadewa University
  • Ni Komang Arini Styawati Warmadewa University, Indonesia
  • I Wayan Kartika Jaya Utama Warmadewa University, Indonesia

DOI:

https://doi.org/10.38142/pjlel.v5i1.2037

Keywords:

Rural Banks (BPR), Misuse of Personal Data, Legal Liability, Personal Data Controller

Abstract

This study examines the legal consequences and legal liability of Rural Banks (Bank Perekonomian Rakyat/BPR) for the misuse of customers' personal data through fictitious credit schemes, an issue left unsettled by the ambiguity of norms in Law Number 27 of 2022 on Personal Data Protection and Law Number 10 of 1998 on Banking. The research employs normative legal research using statutory and conceptual approaches, analyzing primary, secondary, and tertiary legal materials obtained through library research and examined through legal interpretation and legal argumentation. The findings show that the misuse of customers' personal data in fictitious credit practices produces multidimensional legal consequences, namely civil, administrative, criminal, and institutional, stemming from BPR's failure to properly exercise its authority and supervisory function. BPR's liability, as a Personal Data Controller under the Personal Data Protection Law, is institutional rather than merely individual, arising whenever BPR breaches its legal duty to secure customers' data. The study concludes that harmonizing the Personal Data Protection Law, the Banking Law, Law Number 4 of 2023, and Financial Services Authority regulations is necessary to establish clear standards of institutional liability, strengthen internal control and governance, and restore customers' rights.

Downloads

Published

2026-07-29