The Obligation for Banks to Protect Customer Data Privacy
Recently, the Financial Services Authority of Indonesia (Otoritas Jasa Keuangan or “OJK”) issued Financial Services Authority Regulation No. 11/POJK.03/2022 concerning the Implementation of Information Technology by Commercial Banks (POJK No. 11/2022). POJK 11/2022 is a follow-up to the digital transformation blueprint in the banking sector, which regulates the obligations of commercial banks (“Banks”) to protect customers’ data privacy.
Banks that provide services in payment traffic are required to manage data effectively in processing bank data to support the bank’s business objectives. Efforts to manage data effectively at least pay attention to data ownership and management, data quality, data management systems, and data management support resources.
Banks must also implement data privacy protection in processing personal data. Personal data and the principle of protecting data privacy will be adjusted to the provisions of laws and regulations regarding data privacy protection. POJK No. 11/2022 also stipulates that in the event of specific conditions that have the potential to increase the risk for the owner of personal data, the bank is required to conduct an impact assessment on the application of the principle of protecting data privacy.
- As mentioned above, certain conditions include but are not limited to:
- The use of new technologies;
- Customer location and behavior tracking;
- Monitoring the location of public facilities on a large scale; and
- The processing of personal data is sensitive to ethnicity, religion, race, and intergroup.
Suppose the bank is to conduct data exchange activities. In that case, the bank is required to determine at least the classification of personal data, the rights and obligations of the parties involved in the exchange of personal data, personal data exchange agreements, means of exchanging personal data, and personal data security. This personal data exchange must also pay attention to the approval of customers and/or prospective customers, which is carried out in accordance with the provisions of laws and regulations.
Furthermore, if the bank violates the provisions regarding data privacy protection, it may be subject to administrative sanctions in the form of a written warning. However, suppose the bank is subjected to administrative sanctions and still does not meet the provisions for protecting data privacy. In that case, the bank may be subject to sanctions in the form of a ban on issuing new bank products, freezing certain business activities, and/or decreasing the assessment of governance factors in assessing the bank’s soundness level.
If you need consultation regarding financial technology and data privacy, you can contact us at ask@bplawyers.co.id or 082112341235.