Juridical Analysis of the Application of Data Minimization Principles in Mobile Banking According to the Personal Data Protection Law and EU GDPR 2018
DOI:
https://doi.org/10.58355/justices.v4i3.203Keywords:
protection, personal data, data minimizationAbstract
Digital transformation in the banking sector has led to the emergence of mobile banking services such as BRImo, owned by PT. Bank Rakyat Indonesia (Persero) Tbk., which offers customers easy financial transactions. However, behind this innovation, complex issues have arisen regarding compliance with the data minimization principle as stipulated in Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) and the 2018 General Data Protection Regulation (GDPR). This research focuses on the compliance of the personal data processing consent mechanism in the BRImo application with the data minimization principle, as well as the legal consequences of non-compliance with this principle. The research was conducted using a normative juridical approach through a review of relevant laws, doctrines, and legal literature, as well as a sociological juridical approach. The results show that BRImo's non-compliance with the data minimization principle is reflected in the practice of bundled consent without granular options, minimal transparency regarding data purposes and retention, and limited user control to revoke or modify consent. This shifts data consent from a substantial function to a mere administrative formality, ultimately leading to potential criminal and administrative sanctions and reputational risks for service providers. Corrective measures require the implementation of granular consent, interactive privacy dashboards, strict data retention policies, the appointment of a Data Protection Officer (DPO), and internal education to ensure lawful, fair, and proportionate data processing.
Downloads
References
Ahmed, J., et al. (2020). GDPR Compliant Consent Driven Data Protection in Online Social Networks: A Blockchain-Based Approach. 2020 3rd International Conference on Information and Computer Technologies (ICICT), 307–312. https://doi.org/10.1109/ICICT50521.2020.00054
Bahtiar, N. (2022). Darurat Kebocoran Data: Kebuntuan Regulasi Pemerintah. Development Policy and Management Review (DPMR), 2(1), 94.
Disemadi, H. S. (2021). Pelindungan Nasabah Dalam Penerapan Electronic Banking Sebagai Bagian Aktifitas Bisnis Perbankan Di Indonesia. Jurnal Perspektif Administrasi Dan Bisnis, 2(1), 27–40. https://doi.org/10.38062/jpab.v2i1.16
Gultom, L., Saputra, A. F., & Aziz, M. F. (2021). Pelindungan data pribadi di Indonesia Menyikapi Liberalisasi Ekonomi Digital. Indonesia for Global Justice.
Indriani, M., & Putri, A. A. (2023). Persetujuan Dinamis sebagai Sarana Optimalisasi Pelindungan Data Pribadi dan Hak atas Privasi. Jurnal HAM, 14(2), 105–122. https://doi.org/10.30641/ham.2023.14.105-122
Indriani, M., & Widiati, E. P. (2019). The Privacy Challenge in the ‘Smart Era’: A Study of the Implementation of e-Government in Surabaya. ICPS 2018 Proceeding, 641–644. https://doi.org/10.5220/0007548606410644
Irsyad, F. R., Siregar, F. A., Marbun, J., & Hasyim, H. (2024). Menghadapi Era Baru: Strategi Perbankan Dalam Menghadapi Perubahan Pasar Dan Teknologi di Indonesia. Transformasi: Journal of Economics and Business Management, 3(2).
JDIH Kota Semarang. (2024, Desember 2). Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (PDP): Menjaga Keamanan dan Privasi Data Warga Negara. https://jdih.semarangkota.go.id/artikel/view/undang-undang-nomor-27-tahun-2022-tentang-pelindungan-data-pribadi-pdp-menjaga-keamanan-dan-privasi-data-warga-negara
Kostic, B., & Penagos, E. V. (2017). The freely given consent and the “bundling” provision under the GDPR.
Lubis, D. (2023). Pengaruh Persepsi Kegunaan, Kemudahan dan Keamanan Terhadap Kepuasan Nasabah Menggunakan Mobile Banking. JEKSya Jurnal Ekonomi dan Keuangan Syariah, 2(2), 445.
Pertot, T. (2023). Personal data supplying: the issue of bundled consent. Università degli Studi di Trieste, 3.
Ramdana Irsyad, F., Siregar, F. A., Marbun, J., & Hasyim, H. (2024). Menghadapi Era Baru: Strategi Perbankan Dalam Menghadapi Perubahan Pasar Dan Teknologi di Indonesia. Transformasi: Journal of Economics and Business Management, 3(2).
Riza Diandra Tanjung, & Nurhilmiyah. (2024). Aspek Pelindungan Hukum Atas Data Pribadi Nasabah pada Penyelenggaraan Layanan Mobile Banking pada PT. Bank Rakyat Indonesia Cabang Stabat. Dinasti Review, 4(5).
Rosadi, S. D. (2016). Pelindungan Data Pribadi Sebagai Alat Utama Menjamin Hak Privasi Warga Negara. In Kebebasan Berekspresi di Indonesia: Hukum, Dinamika, Masalah dan Tantangannya, 210.
Schweyen, E. (2018, Maret 7). Making Sense of Consent Under The GDPR. https://blog.returnpath.com/making-sense-consent-gdpr/
Suari, K. R. A., & Sarjana, I. M. (2023). Menjaga Privasi di Era Digital: Pelindungan Data Pribadi di Indonesia. Jurnal Analisis Hukum (JAH), 6(1), 132–146.
Tjatur, H., Debora Irene, C., Wardhana, B., & Riyanto, G. D. (2024). Pelindungan Data Pribadi dalam Jurnalisme dan Media. Jakarta: Asosiasi Media Siber Indonesia.
Vida. (2023, April 18). Peran verifikasi identitas Biometrik Untuk pendaftaran rekening online. https://vida.id/id/blog/the-role-of-biometric-identity-verification-for-online-account-registration
Tiana Dermendjieva. (n.d.). PIPEDA’s Guidelines for Obtaining Meaningful Consent. GDPR Local. https://gdprlocal.com/pipedas-guidelines-for-obtaining-meaningful-consent/
PT Bank Rakyat Indonesia (Persero) Tbk. Pemberitahuan Privasi. https://bri.co.id/privacy
Bank Mandiri. (n.d.). ESG Customer Rights. https://www.bankmandiri.co.id/esg-customer-rights
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Nyimas Safira Septiana, Sinta Dewi, Laina Rafianti

This work is licensed under a Creative Commons Attribution 4.0 International License.



















