Juridical Analysis of the Application of Data Minimization Principles in Mobile Banking According to the Personal Data Protection Law and EU GDPR 2018

Authors

  • Nyimas Safira Septiana Fakultas Hukum, Universitas Padjajaran Bandung
  • Sinta Dewi Fakultas Hukum, Universitas Padjajaran Bandung, Indonesia
  • Laina Rafianti Fakultas Hukum, Universitas Padjajaran Bandung, Indonesia

DOI:

https://doi.org/10.58355/justices.v4i3.203

Keywords:

protection, personal data, data minimization

Abstract

Digital transformation in the banking sector has led to the emergence of mobile banking services such as BRImo, owned by PT. Bank Rakyat Indonesia (Persero) Tbk., which offers customers easy financial transactions. However, behind this innovation, complex issues have arisen regarding compliance with the data minimization principle as stipulated in Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) and the 2018 General Data Protection Regulation (GDPR). This research focuses on the compliance of the personal data processing consent mechanism in the BRImo application with the data minimization principle, as well as the legal consequences of non-compliance with this principle. The research was conducted using a normative juridical approach through a review of relevant laws, doctrines, and legal literature, as well as a sociological juridical approach. The results show that BRImo's non-compliance with the data minimization principle is reflected in the practice of bundled consent without granular options, minimal transparency regarding data purposes and retention, and limited user control to revoke or modify consent. This shifts data consent from a substantial function to a mere administrative formality, ultimately leading to potential criminal and administrative sanctions and reputational risks for service providers. Corrective measures require the implementation of granular consent, interactive privacy dashboards, strict data retention policies, the appointment of a Data Protection Officer (DPO), and internal education to ensure lawful, fair, and proportionate data processing.

Downloads

Download data is not yet available.

References

Ahmed, J., et al. (2020). GDPR Compliant Consent Driven Data Protection in Online Social Networks: A Blockchain-Based Approach. 2020 3rd International Conference on Information and Computer Technologies (ICICT), 307–312. https://doi.org/10.1109/ICICT50521.2020.00054

Bahtiar, N. (2022). Darurat Kebocoran Data: Kebuntuan Regulasi Pemerintah. Development Policy and Management Review (DPMR), 2(1), 94.

Disemadi, H. S. (2021). Pelindungan Nasabah Dalam Penerapan Electronic Banking Sebagai Bagian Aktifitas Bisnis Perbankan Di Indonesia. Jurnal Perspektif Administrasi Dan Bisnis, 2(1), 27–40. https://doi.org/10.38062/jpab.v2i1.16

Gultom, L., Saputra, A. F., & Aziz, M. F. (2021). Pelindungan data pribadi di Indonesia Menyikapi Liberalisasi Ekonomi Digital. Indonesia for Global Justice.

Indriani, M., & Putri, A. A. (2023). Persetujuan Dinamis sebagai Sarana Optimalisasi Pelindungan Data Pribadi dan Hak atas Privasi. Jurnal HAM, 14(2), 105–122. https://doi.org/10.30641/ham.2023.14.105-122

Indriani, M., & Widiati, E. P. (2019). The Privacy Challenge in the ‘Smart Era’: A Study of the Implementation of e-Government in Surabaya. ICPS 2018 Proceeding, 641–644. https://doi.org/10.5220/0007548606410644

Irsyad, F. R., Siregar, F. A., Marbun, J., & Hasyim, H. (2024). Menghadapi Era Baru: Strategi Perbankan Dalam Menghadapi Perubahan Pasar Dan Teknologi di Indonesia. Transformasi: Journal of Economics and Business Management, 3(2).

JDIH Kota Semarang. (2024, Desember 2). Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (PDP): Menjaga Keamanan dan Privasi Data Warga Negara. https://jdih.semarangkota.go.id/artikel/view/undang-undang-nomor-27-tahun-2022-tentang-pelindungan-data-pribadi-pdp-menjaga-keamanan-dan-privasi-data-warga-negara

Kostic, B., & Penagos, E. V. (2017). The freely given consent and the “bundling” provision under the GDPR.

Lubis, D. (2023). Pengaruh Persepsi Kegunaan, Kemudahan dan Keamanan Terhadap Kepuasan Nasabah Menggunakan Mobile Banking. JEKSya Jurnal Ekonomi dan Keuangan Syariah, 2(2), 445.

Pertot, T. (2023). Personal data supplying: the issue of bundled consent. Università degli Studi di Trieste, 3.

Ramdana Irsyad, F., Siregar, F. A., Marbun, J., & Hasyim, H. (2024). Menghadapi Era Baru: Strategi Perbankan Dalam Menghadapi Perubahan Pasar Dan Teknologi di Indonesia. Transformasi: Journal of Economics and Business Management, 3(2).

Riza Diandra Tanjung, & Nurhilmiyah. (2024). Aspek Pelindungan Hukum Atas Data Pribadi Nasabah pada Penyelenggaraan Layanan Mobile Banking pada PT. Bank Rakyat Indonesia Cabang Stabat. Dinasti Review, 4(5).

Rosadi, S. D. (2016). Pelindungan Data Pribadi Sebagai Alat Utama Menjamin Hak Privasi Warga Negara. In Kebebasan Berekspresi di Indonesia: Hukum, Dinamika, Masalah dan Tantangannya, 210.

Schweyen, E. (2018, Maret 7). Making Sense of Consent Under The GDPR. https://blog.returnpath.com/making-sense-consent-gdpr/

Suari, K. R. A., & Sarjana, I. M. (2023). Menjaga Privasi di Era Digital: Pelindungan Data Pribadi di Indonesia. Jurnal Analisis Hukum (JAH), 6(1), 132–146.

Tjatur, H., Debora Irene, C., Wardhana, B., & Riyanto, G. D. (2024). Pelindungan Data Pribadi dalam Jurnalisme dan Media. Jakarta: Asosiasi Media Siber Indonesia.

Vida. (2023, April 18). Peran verifikasi identitas Biometrik Untuk pendaftaran rekening online. https://vida.id/id/blog/the-role-of-biometric-identity-verification-for-online-account-registration

Tiana Dermendjieva. (n.d.). PIPEDA’s Guidelines for Obtaining Meaningful Consent. GDPR Local. https://gdprlocal.com/pipedas-guidelines-for-obtaining-meaningful-consent/

PT Bank Rakyat Indonesia (Persero) Tbk. Pemberitahuan Privasi. https://bri.co.id/privacy

Bank Mandiri. (n.d.). ESG Customer Rights. https://www.bankmandiri.co.id/esg-customer-rights

Downloads

Published

2025-08-06

How to Cite

Nyimas Safira Septiana, Sinta Dewi, & Laina Rafianti. (2025). Juridical Analysis of the Application of Data Minimization Principles in Mobile Banking According to the Personal Data Protection Law and EU GDPR 2018. JUSTICES: Journal of Law, 4(3), 154–168. https://doi.org/10.58355/justices.v4i3.203

Similar Articles

1 2 3 4 5 > >> 

You may also start an advanced similarity search for this article.