Jurnal Hukum Replik ISSN 2337-9251 (Prin. 2597-9094 (Onlin. Vol. 12 Issue 2 . 1Ae33 DOI: 10. 31000/jhr. Available online since: Sept 20, 2024 Legal Protection For Bank Customers In The Use Of E-Kyc In Opening New Accounts Online As A Form Of Digital Financial Innovation (Study At The Jakarta Head Office Of The State Savings Ban. Jenrico Louis Hutabarat A Universitas Sumatera Utara Sunarmi Universitas Sumatera Utara Detania Sukarja Universitas Sumatera Utara Syarifah Lisa Andriati Universitas Sumatera Utara A jenrico. hutabarat94@gmail. Abstract This research examines the function of E-KYC in Indonesian banking, the responsibility of banks to protect customers' personal data, and the form of data protection at BTN Jakarta Head Office, using analytical descriptive normative legal methods with a statutory approach. POJK Number 23/POJK. 01/2019 allows customer verification through electronic means to replace direct meetings, where E-KYC is implemented as Customer Due A 2024 Authors. Jurnal Hukum Replik is a Journal for Indonesian Procedural Law Studies published biannually by the Faculty of Law. Universitas Muhammadiyah Tangerang. Indonesia. This work is licensed under a Creative Commons Attribution-ShareAlike 4. 0 International License. All writings published in this journal are personal views of the authors and do not represent the views of this journal and the author's affiliated History or Article: Submitted 01/01/2024 Revised 02/02/204 Accepted 03/03/2024 Diligence which includes electronic identification, verification, and The E-KYC organizing bank is required to meet the aspects of security, interconnectivity, system compatibility, technical support, and guarantee of service sustainability to be registered as a PSE, with sanctions from warnings to license revocation if negligent, as has been applied by BTN Mobile, which is registered as a domestic private PSE with international standard security technology to bridge the principle of knowing the customer and the right to privacy. Keywords E-KYC. BTN Mobile. Personal Data Protection. Introduction Banking institutions are one of the financial systems of a country. The important role of banks is seen as having strategic value as intermediaries for parties who have excess funds . urplus of fund. with parties who lack and need funds . ack of fund. thus banks will be engaged in credit activities and various services provided to serve financing needs and launch payment system mechanisms for all sectors of the economy. Banks are financial institutions that are a place for individuals, private business entities, state-owned enterprises and also government institutions to save their funds through various service activities provided and serve the need for financing, launching a payment system for all sectors of the economy. Banks as a financial institution that collects funds from the public in the form of savings and deposits, and carries out its activities based on public trust, must truly maintain public 1 Muhammad Djumhana. Hukum Perbankan di Indonesia, (Bandung: PT Citra Aditya Bakti, 2. , hlm. XV. 2 Chairil Susanto. Legal Opini. Jurnal Ilmu Hukum. Vol. 2 No. Tahun 2014. Legal Protection For Bank Customers In The Use Of E-KycA. Banks are not only tasked with collecting public funds in the form of deposits directly to channel them back to the community, but are obliged to maintain the confidentiality of their customers' data as 3 Banking institutions are also an agent of trust from the public or customers given the existence of one of the principles of bank management, namely the principle of trust . iduciary principl. , so that banks in providing loans in the form of credit are always guided by the prudential banking principle. According to Hikmahanto Juwana, the banking industry has special characteristics that can be seen from two things, namely banking is one of the subsystems of the financial services industry, and banking is also an industry that relies heavily on public trust. One of the ways banks run their business is by collecting public funds as customers. that banks are institutions that rely on public funds, and banks also have a burden on public trust in the way funds are managed so as not to cause losses to the community. As a result, banks must apply the prudential principle in managing their business. This prudential principle aims to maintain the trust of the depositing public and the creation of healthy In relation to the application of the principle of prudential banking in regulating the traffic of banking activities, one of the efforts so that the principle can be applied is the application of the know your 3 Sentosa Sembiring. Hukum Perbankan. (Bandung: CV Mandar Maju, 2. Hlm. Lukmanul Hakim. AuAnalisis Alternatif Penyelesaian Sengketa Antara Pihak Nasabah Dengan Industri Jasa Keuangan Pada Era Otoritas Jasa KeuanganAy. Jurnal Keadilan Progresif. Vol. 6 No. Tahun 2015. Hlm. 5 Devy Kusuma Wati. KYC Sebagai Peran Perbankan Dalam Pemberantasan TPPU, https://w. id/siaran_pers/read/968/kyc-sebagai-peran-perbankan-dalampemberantasan-tppu. html , diakses tanggal 23 Mei 2023. customer principle. 6 The application of the Know You Customer (KYC) principle by banks can be seen in the creation of new accounts by customers, namely to determine the identity of customers, monitor transactions or large transactions. KYC principles are realized through the implementation of customer acceptance policies, customer identification policies and procedures, monitoring of customer accounts and transactions, and risk management. Individuals have the right to determine whether or not to share or exchange their personal data. In addition, individuals also have the right to determine the conditions under which the transfer of personal data will take place. Furthermore, personal data protection also relates to the concept of the right to privacy. The right to privacy has evolved so that it can be used to formulate the right to protect personal data. In this case. Law Number 27 of 2022 concerning Personal Data Protection regulates that Personal Data Subjects are entitled to obtain information about the clarity of identity, the basis of legal interests, the purpose of requesting and using Personal Data and the accountability of the party requesting Personal Data. 10 Adequate protection of Personal Data will be able to give the public confidence to provide Personal Data for the benefit of the greater community without being abused or violating their personal rights so that it will create a balance 6 Ibid. Pasal 1 ayat 2 Peraturan Bank Indonesia nomor 3/10/PBI tahun 2001. 8 Ibid. Pasal 2 ayat 2. 9 Human Rights Committee General Comment No. on the right to respect of privacy, family, home and correspondence, and protection of honour and reputation . seperti yang dikutip dalam Privacy International Report, 2013, hlm. 10 Pasal 5 Undang-Undang Nomor 27 tahun 2022 tentang Perlindungan Data Pribadi. Legal Protection For Bank Customers In The Use Of E-KycA. between the rights of individuals and the community whose interests are represented by the state. The utilization of information technology for the banking industry in the innovation of bank service products is also overshadowed by the potential risk of system failure and/or the risk of electronic crime . committed by irresponsible people. System failure can be caused by system malfunction . uch as server dow. , and on a wider scale can be caused by natural disasters. Meanwhile, cybercrime that occurs in the banking industry in Indonesia tends to increase in Indonesia such as identity theft, carding, hacking, cracking, phishing, viruses, cybersquating. ATM fraud, and others. In practice, consumers' personal information has been traded through agents without seeking prior permission from the information A common case in Indonesia is the buying and selling of consumer data. Consumers whose data is successfully obtained become marketing targets for a company or individual product. Not a few internet users also offer account or follower buying and selling services. In fact, this practice opens up space for misuse of a person's data to commit crimes. Examples of data leaks that result in data misuse that have occurred in banking include the following: On May 8, 2023. Bank Syariah Indonesia experienced a ransomware attack by the hacker group Lockbit 3. The perpetrators claimed to have stolen 1. 5 terabytes of customer data, financial documents, legal documents, confidentiality 11 Penjelasan Undang-Undang Nomor 27 Tahun 2022 tentang Perlindungan Data Pribadi. 12https://ditjenpp. id/index. php?option=com_content&vi ew=article&id=665:tanggung-jawab-penyelenggara-sistem-elektronik-perbankandalam-kegiatan-transaksi-elektronik-pasca-uu-no-11-tahun-2008&catid=107:hukumteknologi-informasi&Itemid=187&lang=en , diakses pada tanggal 23 Mei 2023. agreements, and passwords for internal access and company Data of two million BRI Life customers is suspected of being leaked and sold online. Information about the leak of BRI Life customer data was uploaded by a Twitter account on Tuesday. July 27, 2021. In the upload, it was written that the perpetrator threatened to sell sensitive data belonging to BRI Life. The hacker allegedly stole 250 gigabytes of the insurance company's customer data and sold it for US$ 7,000 or IDR 5 million. Customer data leak incidents have the potential to cause the risk of loss of data subject reputation, loss of confidentiality and integrity of personal data, and potential financial loss. Banking data leaks cannot be separated from the level of security of the electronic system used. This means that Electronic System Organizers . n this case banks and third partie. have a crucial role in complying with the procedures for organizing electronic systems as stipulated in Government Regulation Number 71 of 2019 concerning the Implementation of Electronic Systems and Transactions. The hardware used by Electronic System Organizers must meet the following requirements:15 Fulfilling the aspects of security, interconnectivity and compatibility with the system used. 13 Mediana. Kominfo Bersama BSSN Selidiki Insiden Kebocoran Data Pribadi BSI, https://w. id/baca/ekonomi/2023/05/16/kominfo-akan-koordinasi-bssnmendalami-insiden-kebocoran-data-pribadi-bsi , diakses pada tanggal 23 Mei 2023. 14 Fransisca Christy Rosana. Kebocoran Data Nasabah BRI Life Bukti Lemahnya Proteksi dan Regulasi, https://fokus. co/read/1488710/kebocoran-datanasabah-bri-life-bukti-lemahnya-proteksi-dan-regulasi , diakses pada tanggal 23 Mei 2023. 15 Pasal 7 ayat . Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik. Legal Protection For Bank Customers In The Use Of E-KycA. Having technical support, maintenance and/or after-sales services from the seller or provider. Having a guarantee of service continuity. Fulfillment of these requirements must be done through certification or other similar evidence. Based on the background above, there are at least 3 . reasons why this research is important to be conducted: First, there is a conflict between the principle of knowing the customer and the right to privacy which should be bridged with personal data protection. Second. OJK Regulations have not accommodated regulations regarding Bank accountability in the event of a data leak. Third, the electronic system run by the Bank must have technical certification and there is no supervision in the context of overcoming data transaction leaks so that it can reduce efforts to protect customer data. This study aims to discuss in depth the implementation of the principle of knowing your customer electronically at BTN Head Office Jakarta, which was chosen because it is the largest state-owned bank in the center of the Indonesian economy with high transaction complexity, with the formulation of the problem including: the function of E-KYC in organizing banking services in Indonesia, the legal responsibility of the Bank in protecting Customer Personal Data related to E-KYC practices, and the form of protection of Customer Personal Data implemented by BTN Head Office Jakarta in the implementation of EKYC. Method 16 Pasal 7 ayat . Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik. The research method used is normative juridical, with a statute approach17 and case approach to study the use of e-KYC in opening new accounts online at BTN Head Office Jakarta. The research is descriptive in nature using secondary data as the main source, consisting of primary legal materials . egislation and interview result. , secondary legal materials . ooks, research results, articles, journal. , and tertiary legal materials . eneral dictionaries, legal dictionarie. Data collection techniques were carried out through literature studies and in-depth interviews with BTN Head Office Jakarta employees. 18 Data analysis uses qualitative methods, by describing data in a quality manner in the form of regular, logical and systematic sentences to obtain conclusions that answer research problems. Result And Discussion E-KYC as a Form of Implementation of the Principle of Prudence and Knowing the Customer in Bank Account Opening Services Know Your Customer (KYC) in practice is implemented with the term Customer Due Diligence (CDD) which applies to every activity in the form of identification, verification and monitoring carried out by the Bank and ensures that the transaction is in accordance with the customer profile. The term CDD has the same meaning as KYC, namely understanding the character of the customer's transaction whether it is in accordance 17 Koto. The Potential Of Traditional Knowledge As An Improvement Of The Welfare Of Communal Communities. DE LEGA LATA: Jurnal Ilmu Hukum, 9. , 162-169. 18 Fathin. , & Koto. A Juridical Review of Transgender Heirs from the Perspective of Islamic Law and Civil Law. JHR (Jurnal Hukum Repli. , 12. , 19 Simatupang. Pelaksanaan Sistem Peradilan Pidana Anak Di Indonesia Perspektif Nilai Keadilan. Jurnal Yuridis, 11. , 54-63. Legal Protection For Bank Customers In The Use Of E-KycA. with the profile or not, and if it is not in accordance, whether there is an element of suspicious transactions in the transaction. Customer Due Diligence (CDD) is implemented in the form of a bank's obligation to identify potential customers to find out the potential customer's profile and verify the information and supporting documents of potential customers at the start of a business relationship. 20 Verification of the truth of the prospective customer's identity is carried out through a direct meeting . ace to fac. in order to ensure the truth of the prospective customer's identity. 21 The verification process through direct meetings . ace to fac. can be replaced by verification through electronic means belonging to the bank or a third party that has received approval from the Financial Services Authority (OJK). 22 Exceptions to verification through direct meetings are implemented with the following provisions: Verification is carried out through electronic processes and means owned by PJK and/or owned by prospective Verification must utilize population data that meets 2 . authentication factors. Verification through electronic means is often referred to as Electronic-Know Your Customer (E-KYC). Banks are required to identify and classify Prospective Customers or Customers into groups of individuals . atural person. Corporations, and other legal arrangements. 20 Pasal 17 ayat . POJK Nomor 23 /POJK. 01/2019 tentang Perubahan Atas POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 21 Pasal 17 ayat . POJK Nomor 23 /POJK. 01/2019 tentang Perubahan Atas POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 22 Pasal 17 ayat . POJK Nomor 23 /POJK. 01/2019 tentang Perubahan Atas POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 23 Pasal 19 POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. Identification of Prospective Customers to find out the profile of Prospective Customers is done by requesting data and information which at least includes: 24 For prospective customers who are individuals . Identity containing: full name including aliases . f an. identity document number. residential document and other residential addresses . place and date of birth. address and telephone number of workplace . marital status. identity of the Beneficial Owner, if any. source of funds. average income per year. the intent and purpose of the business relationship or transaction to be carried out by the Prospective Customer. 24 Pasal 20 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. Legal Protection For Bank Customers In The Use Of E-KycA. For prospective customers who are natural persons, the above information must be supported by the prospective customer's identity documents and signature specimen. for Prospective Corporate Customers: permit number from the authorized agency. field of business or activity. domicile address. place and date of establishment. form of legal entity or business entity. identity of the Beneficial Owner if the Prospective Customer has a Beneficial Owner. source of funds. intent and purpose of the business relationship or transaction to be carried out by the Prospective Customer. For Prospective Corporate Customers in the form of companies classified as micro and small businesses plus: 26 . signature specimen and power of attorney to the appointed party who has the authority to act for and on behalf of the company in conducting business relations with PJK. 25 Pasal 21 POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 26 Pasal 22 ayat . huruf a POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. NPWP card for Customers who are required to have NPWP in accordance with the provisions of laws and . business permit or other documents required by the authorized agency. For Prospective Corporate Customers in the form of companies that are not classified as micro and small businesses and for Prospective Customers other than Prospective Customers who are natural persons and Corporations in the form of companies, supplemented with the following supporting documents:27 . financial statements or descriptions of the company's business activities. company management structure. company ownership structure. identity documents of members of the Board of Directors or power of attorney of members of the Board of Directors who are authorized to represent the company to conduct business relations. For Prospective Corporate Customers in the form of foundations, please provide the following supporting documents:28 . foundation activity permit. description of foundation activities. Pasal 22 ayat . huruf b POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 28 Pasal 22 ayat . huruf b POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. Legal Protection For Bank Customers In The Use Of E-KycA. structure and name of foundation management. identity documents of management members or power of attorney from management members who are authorized to represent the foundation to conduct business relations with the Bank. For Prospective Corporate Customers other than companies and foundations, whether they are legal entities or not, please provide the following supporting documents: 29 . proof of permit from the authorized agency. name of the Corporation. deed of establishment and/or articles of association and bylaws (AD/ART). identity document of the authorized party representing the Corporation in conducting business relations with the PJK. for prospective customers of other obligations . permit number from the authorized agency . f an. domicile address. form of agreement . egal arrangemen. identity of the Beneficial Owner if the Prospective Customer has a Beneficial Owner. source of funds. 29 Pasal 23 ayat . huruf b POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan . intent and purpose of the business relationship or transaction to be carried out by the Prospective Customer. For prospective customers in the form of other agreements . egal arrangement. plus the following supporting documents:30 . proof of registration with the authorized agency. name of the agreement. deed of establishment and/or articles of association and bylaws (AD/ART) . f an. identity document of the authorized party representing the other agreement . egal arrangemen. in conducting business relations with the Bank. For prospective customers in the form of state institutions, government agencies, international institutions and foreign country representatives. PJK is required to request information regarding the name and address of the institution, agency or representative office. This information must be supported by documents including:32 . a letter of appointment for the authorized party representing the institution, agency or representative in conducting business relations. 30 Pasal 23 ayat . huruf c POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 31 Pasal 24 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 32 Pasal 24 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. Legal Protection For Bank Customers In The Use Of E-KycA. specimen representing the institution, agency or representative in conducting business relations. The Bank is required to verify the information and supporting documents of the Prospective Customer as referred to above, based on documents and/or other reliable and independent sources of information and ensure that the data is current. 33 Verification is carried out to ensure that the party acting for and on behalf of the Customer has obtained authorization from the Customer, and to identify and verify the identity of the party. 34 Mandatory verification is based on the risks of Money Laundering and/or Terrorism Financing that have been identified based on risk assessments conducted by the Bank. The Bank may conduct interviews with Prospective Customers to examine and verify the validity and truth of documents, in the event of any doubt regarding the data, information and/or supporting documents received. 36 In case of doubt, the Bank is obliged to ask the Prospective Customer to provide more than one identity document issued by an authorized party to ensure the authenticity of the Prospective Customer's identity. 37 In the event that the Bank has implemented risk management procedures, the PJK may conduct business relations or transactions before the Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 34 Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 35 Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 36 Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 37 Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. verification process is complete. 38 The verification process must be completed as soon as possible, after the customer's business relationship with the PJK occurs, taking into account that the risks of Money Laundering and Terrorism Financing can be managed effectively and that this direct meeting process does not disrupt normal business activities. Banks are required to ensure that Prospective Customers. Customers, or WICs who open business relationships or conduct transactions act for themselves or for the benefit of the Beneficial Owner. 40 In the event that a Prospective Customer. Customer, or WIC acts in the interests of the Beneficial Owner, the Bank is required to carry out CDD towards the Beneficial Owner. 41 In the case where the Beneficial Owner is classified as a Politically Exposed Person, the procedure applied is the EDD 42 In the event that there is a difference in risk level between the Prospective Customer. Customer, or WIC and the Beneficial Owner, the implementation of CDD is carried out following the higher risk level. 43 The obligation to carry out CDD towards Beneficial Owners applies to prospective Customers. Customers or WICs who have a low risk level. Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 39 Pasal 25 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 40 Pasal 27 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 41 Pasal 27 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 42 Pasal 27 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 43 Pasal 27 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. 44 Pasal 27 ayat . POJK Nomor 12/POJK. 01/2017 tentang Penerapan Program Anti Pencucian Uang dan Pencegahan Pendanaan Terorisme di Sektor Jasa Keuangan. Legal Protection For Bank Customers In The Use Of E-KycA. Bank's Responsibility in Maintaining Customer's Personal Confidentiality in Relation to E-KYC Practices The principle of confidentiality means that a customer's personal data must be kept confidential, especially in the era of digital banking. Based on Financial Services Authority Regulation Number 12/POJK. 03/2018 concerning the Provision of Digital Banking Services by Commercial Banks, optimal utilization of information technology developments is a requirement to support innovation in banking services. Therefore, digital banking services are now increasingly used by banks. As a provider of digital banking services, of course, a bank must pay attention to the requirements as stipulated in Financial Services Authority Regulation Number 12/POJK. 03/2021 concerning Commercial Banks, namely: have a business model with the use of innovative and safe technology in serving customer needs. have the ability to manage a prudent and sustainable digital banking business model. have adequate risk management. fulfill aspects of governance including the fulfillment of a Board of Directors who have competence in the field of information technology and other competencies in OJK assessment of the ability and propriety of the main parties of financial services institutions. implement protection of customer data security. provide efforts that contribute to the development of the digital financial ecosystem and/or financial inclusion. Based on these requirements, it can be seen that customer data security is an important point in the implementation of digital banking services. The Banking Law as the basis for all banking services has also stipulated and provided legal protection for customer personal data, namely in Article 29 paragraph . of the Banking Law which states that for the benefit of customers, banks are required to provide information regarding the possibility of a risk of loss in connection with customer transactions carried out through the bank. Furthermore, provisions regarding bank confidentiality are also regulated in the provisions of Article 40 paragraph . of the Banking Law, namely that banks are required to keep confidential information regarding depositing customers and their deposits, except for tax purposes45, accounts receivable settlement46, judicial interests in criminal cases47, exchange information between banks 48, and the party appointed by the customer or his heirs. The provisions of bank secrecy in the Banking Law give rise to the logical consequence of criminal sanctions for those who violate it. The criminal sanctions for violations of bank secrecy are regulated in Articles 47 and 47 A of the Banking Law as follows: Article 47 of the Banking Law reads: 45 Lihat Pasal 41 UU Perbankan. 46 Lihat Pasal 41 A UU Perbankan. 47 Lihat Pasal 42 UU Perbankan. 48 Lihat Pasal 44 UU Perbankan. 49 Lihat Pasal 44 A UU Perbankan. Legal Protection For Bank Customers In The Use Of E-KycA. Anyone who, without a written order or permission from the Head of Bank Indonesia as referred to in Article 41. Article 41A and Article 42, intentionally forces a bank or Affiliated Party to provide information as referred to in Article 40, shall be subject to imprisonment for a minimum of 2 . years and a maximum of 4 . years and a fine of a minimum of IDR 10,000,000,000. en IDR 200,000,000,000. wo hundred billion rupia. Members of the Board of Commissioners. Directors, bank employees or other Affiliated Parties who intentionally provide information that must be kept confidential according to Article 40, shall be subject to imprisonment of at least 2 . years and a fine of at least IDR 4,000,000,000. our billion rupia. and a maximum of IDR 8,000,000,000. ight billion rupia. Article 47 A of the Banking Law reads: "Members of the Board of Commissioners. Board of Directors, or bank employees who intentionally do not provide the information required as referred to in Article 42A and Article 44a, shall be subject to imprisonment for a minimum of 2 . years and a maximum of 7 . years and a fine of a minimum of IDR 4,000,000,000. our billion rupia. and a maximum of IDR 15,000,000,000. ifteen billion rupia. In relation to the implementation of electronic systems and transactions, violations of the implementation of the principle of personal data protection may be subject to administrative 50 The imposition of these sanctions is only aimed at parties who commit administrative violations, while violations of a moral or civil nature are not subject to administrative 51 The imposition of administrative sanctions can be in the form of:52 written warning. administrative fine. temporary suspension. termination of access. and/or removal from the list. The provisions of sanctions stipulated by laws and regulations provide legal responsibility for banks to ensure that there are no leaks of bank secrets. Banks are therefore required to act in good faith in carrying out their business activities and to guarantee their business activities based on applicable banking standards. The Financial Services Authority as a regulator, supervisor, examiner, and investigator in banking deposits can also help customers to obtain more certain legal protection. OJK's supervision of banking covers all aspects of a bank's operations, from institutional aspects, product and activity aspects, prudential aspects, to transparency aspects. This 50 Pasal 100 ayat . Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik. 51 Penjelasan Pasal 100 ayat . Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik. 52 Pasal 100 ayat . Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik. 53 Djumhana. Hukum Perbankan di Indonesia, (Bandung: Citra Aditya Bakti, 1. , hlm. Legal Protection For Bank Customers In The Use Of E-KycA. supervision uses risk-based supervision strategies and methodologies to detect significant risks early and take appropriate and timely supervisory actions. The stages of supervision carried out by OJK include understanding the supervised bank, conducting bank risk assessments, preparing a supervision plan based on identified risks, conducting bank inspections, and monitoring bank conditions periodically. The legal protection provided by OJK to customers or consumers in banking is guided by Article 2 paragraph . of POJK Number 6/POJK. 07/2022 concerning Consumer and Community Protection in the Financial Services Sector, namely by implementing the principles of: adequate education, openness and transparency of information, fair treatment and responsible business behavior, protection of assets, privacy and consumer data as well as effective and efficient handling of complaints and dispute resolution. Protection of Personal Data of BTN Bank Customers. Central Branch. Jakarta in the Implementation of E-KYC Personal Data of BTN Bank Customers obtained will be grouped into 4 categories, namely confidential personal data, restrictive personal data, general personal data and personal data for internal purposes, where each category is protected with a password to access it. Furthermore, the exchange or distribution of personal data is not permitted using social media by employees who are required to use Microsoft Things or via verified email for use by Bank Tabungan Negara. Each employee is also given a special user account to access the personal data, where the account password will be changed periodically. Bank BTN through BTN Mobile ensures the security of its transactions and data storage by using three methods, namely 54 Wawancara dengan Mohammad Anugrah Putra. Staf Compliance Management & Governance Division (CMGD) Bank BTN Cabang Pusat Jakarta, pada tanggal 8 Juni 2023. BTN Mobile uses international standard security technology, namely by using the latest data security and encryption technology that meets international standards, namely the endpoint protection platform55. Instrusion Detection System (IDS)56. Security Incident and Event Management (SIEM)57. Web Application Firewall (WAF)58, and Privilege Access Management (PAM)59. Second. BTN Mobile implements layered data isolation and protection by asking customers to enter PIN, password. CVV, and OTP . ne time passwor. repeatedly on the Third. BTN Mobile has been supervised by Bank Indonesia (BI) and the Financial Services Authority (OJK). This supervision exists because BTN Mobile is a supporting application for banking services owned by Bank BTN. The purpose of this supervision is so that all financial services activities in the financial services sector are carried out regularly, fairly, transparently, and accountably, and are able to realize a Endpoint protection platform adalah solusi keamanan yang digunakan pada perangkat perusahaan untuk mencegah serangan dunia maya, mendeteksi aktivitas berbahaya, dan memberikan kemampuan remediasi instan. 56 Intrusion Detection System atau IDS adalah sebuah sistem yang memonitor trafik jaringan untuk mendeteksi aktivitas-aktivitas mencurigakan. Jika aktivitas mencurigakan tersebut ditemukan. IDS akan melaporkannya dalam bentuk Dengan kata lain. IDS bisa dibilang sebagai perangkat lunak pemindai sistem atau jaringan guna terhindar dari kegiatan yang melanggar kebijakan. 57 Security Incident and Event Management (SIEM) merupakan sistem yang membantu anda untuk memonitor lalu lintas jaringan dan memberikan analisa secara real-time dari log yang dihasilkan oleh aplikasi ataupun perangkat keamanan. 58 Web Application Firewall (WAF) merupakan aplikasi Firewall untuk aplikasi HTTP yang berfungsi ntuk melindungi website secara spesifik dari ancaman serangan berbasis web dalam lapisan aplikasi. 59 Privileged access management (PAM) adalah sistem keamanan identitas yang membantu melindungi organisasi dari ancaman cyber dengan memantau, mendeteksi, dan mencegah akses istimewa yang tidak sah ke sumber daya penting. Legal Protection For Bank Customers In The Use Of E-KycA. financial system that grows sustainably and stably, and is able to protect the interests of consumers and the community. Customers can also contact the 24-hour Call Center to handle complaints from BTN customers who have implemented 3 Lines of Defense (LD) in cybersecurity governance such as IT Security . 5 LD). IT Risk and IT Compliance . LD) and IT Audit . LD). Every e-Channel initiative and IT capability development, he said the company always carries out information security reviews and obtains approval from the Financial Services Authority (OJK) and the bank. In this case. Bank BTN has adopted the provisions of the OJK regulator POJK No. 11/POJK. 05/2022 concerning the Implementation of Information Technology by Commercial Banks. In relation to customer data protection, the BTN Mobile electronic system has been registered as a domestic private Electronic System Provider (PSE) by the Ministry of Communication and Information with PSE Registration Number: 001813. 06/DJAI. PSE/12/2021 dated December 21, 62 Regarding cyberspace security. Bank BTN collaborates with the National Cyber and Crypto Agency (BSSN) to cooperate in protecting information and electronic transactions based on the Memorandum of Understanding between PT. Bank Tabungan Negara (Perser. Tbk and the National Cyber and 60 Wawancara dengan Mohammad Anugrah Putra. Staf Compliance Management & Governance Division (CMGD) Bank BTN Cabang Pusat Jakarta, pada tanggal 8 Juni 2023. 61 Ibid. 62 Direktorat Tata Kelola Aptika Kementerian Komunikasi dan Indormatika. Daftar PSE Domestik, https://pse. id/tdpse-detail/2826 , diakses pada tanggal 11 Juni 2023, pukul 19. 53 WIB. Crypto Agency concerning the Protection of Information and Electronic Transactions Number 28/MOU/DIR/2022. Number PERJ. 631/KABSSN/HK. 01/09/2022 dated September 25, 63 The existence of registration as a domestic private Electronic System Provider (PSE) implementation of BTN Mobile has met the minimum requirements as stipulated in the provisions of Government Regulation Number 71 of 2019 concerning the Implementation of Electronic Systems and Transactions. The supporting factors for the development of BTN Mobile are as follows:64 Information security is one of the pillars whose implementation and investment continues to be improved, including people, processes, and technology. Acceleration of the addition of payment and purchasing service features on all digital service channels by implementing efficient and effective partnership and application development processes. From the technology side, security uses the latest technology such as data at rest . ncryption and data maskin. , data on transit . ata security on the internet network or VPN) and data at use . nti-dumping technology or data lost preventio. 63 Badan Siber dan Sandi Negara. BSSN dan BTN Sepakati Kolaborasi untuk Tingkatkan Keamanan Transaksi Elektronik, https://bssn. id/bssn-dan-btn-sepakatikolaborasi-untuk-tingkatkan-keamanan-transaksi-elektronik/ , diakses pada tanggal 11 Juni 2023, pukul 19. 57 WIB. 64 Wawancara dengan Mohammad Anugrah Putra. Staf Compliance Management & Governance Division (CMGD) Bank BTN Cabang Pusat Jakarta, pada tanggal 8 Juni 2023. Legal Protection For Bank Customers In The Use Of E-KycA. From the process side, testing or drill test or pentest to assess whether security on the technology side is effective involving 3 tiers, namely IT. Risk and Compliance, and Audit. From the human resources aspect. BTN provides routine socialization to internal teams and also to customers to help protect data related to transactions such as account numbers. PINs. Passwords, and other personal data. Meanwhile, the factors inhibiting the development of BTN Mobile are as follows:65 The use of gadgets is dominated by millennials born between 1990 and early 2000. There are still many older people who still choose conventional banking services because they do not know how to use gadgets, which has an impact on the use of electronic-based banking services. Public trust in the security system, especially regarding personal data information, is not evenly distributed across all levels of society, this is influenced by cases of account hacking or the spread of personal data information that is detrimental to customers. The market is limited only to internet users who are generally middle to upper class and educated. The internet network is not evenly distributed throughout Indonesia. 65 Ibid. In order to anticipate the impact of acceptable risks, customers must also take part in maintaining the security of their personal data, namely by educating themselves about the importance of maintaining personal data information. This education can be obtained through the bank, such as staff, crew, sales, service points, and others. Currently, channels and campaigns that provide information about the misuse of personal data have also been widely carried out. So that customers can know how to protect their personal data, such as not sharing passwords, not sharing PINs, not sharing OTP codes, and not using passwords that are too easy such as birth dates. The loss of customer funds or the spread of personal data in digital banking applications can be caused by various factors, both from errors on the part of the bank, the customer, or due to errors on the part of a third party. Of course, the losses experienced by the customer must be resolved in the form of The accountability given also varies according to the cause of the problem that occurs. Bank BTN has established several complaint channels that can be accessed for customers to submit written or verbal complaints, namely the contact center 150286/1500286, website: btncontactcenter@btn. id, and Bank BTN's official social Customers who submit complaints will be verified by Bank BTN and then the customer will receive a complaint Bank BTN will follow up and resolve the complaint and 66 Ibid. Legal Protection For Bank Customers In The Use Of E-KycA. if the customer does not agree with the results of the settlement, they can continue the process at the Alternative Dispute Resolution Institution for the Financial Services System (LAPS SJK) or the judiciary. This is in accordance with the provisions of POJK Number 6/POJK. 07/2022 concerning Consumer and Community Protection in the Financial Services Sector. Bank BTN is obliged to be responsible for Consumer losses arising from errors, negligence, and/or actions that are contrary to the provisions of laws and regulations in the financial services sector, carried out by the Board of Directors. Board of Commissioners. Employees, and/or third parties who work for or represent the interests of Bank BTN. Bank BTN as an electronic system organizer is legally responsible for the implementation of the electronic system. The parties responsible for all legal consequences in the implementation of electronic transactions are:67 implementation of Electronic Transactions are the responsibility of the parties to the transaction. if a power of attorney is given, all legal consequences in the implementation of Electronic Transactions are the responsibility of the grantor of the power of attorney. if done through an Electronic Agent, all legal consequences in the implementation of Electronic 67 Lihat Pasal 21 Undang-Undang Nomor 11 Tahun 2018 tentang Informasi dan Transaksi Elektronik sebagaimana diubah dengan Undang-Undang Nomor 19 Tahun 2016. Transactions are the responsibility of the Electronic Agent organizer. Bank BTN's responsibility for losses experienced by customers is to assist in the customer complaint process and conduct examinations/investigations in accordance with bank procedures and assist customers in finding solutions to losses experienced by customers such as making reports to the police for further handling. Bank BTN is also responsible for the maintenance of the BTN Mobile application to maintain the security and comfort of its customers in the future. Bank BTN will deactivate BTN Mobile access via the site to minimize the risk of social engineering attempts by cybercriminals. In addition. Bank BTN has also implemented a one-connected device policy to protect customers' BTN Mobile accounts. This is done so that BTN Mobile account owners can only access and transact using their accounts via one verified device. Conclusion E-KYC is implemented through Customer Due Diligence which includes identification, verification, and electronic monitoring to ensure that transactions match customer profiles, where banks must meet aspects of security, interconnectivity and compatibility, with BTN Mobile having been registered as a domestic private PSE number 06/DJAI. PSE/12/2021 standard security technology, layered data protection, and supervision by BI and OJK. Meanwhile, there are still many customers who do not understand the importance of protecting personal data so that socialization is needed by the government and banks, which must implement clean and clear governance and always strive for the best Legal Protection For Bank Customers In The Use Of E-KycA. security system to mitigate risks and prevent misuse of customer data by irresponsible parties. References