MANAGING INDONESIAN DATA BREACH NOTIFICATION IN THE FINANCIAL SERVICES SECTOR: A CASE FOR ONE-STOP NOTIFICATION MODEL

##plugins.themes.academic_pro.article.main##

Muhammad Deckri Algamar
Prof. Abu Bakar Munir
Hendro

Abstract

As a business of trust, the banking and financial services industry must protect its reputation to ensure consumer’s confidence. However, recent adoption of emerging internet communication technologies (ICT) have introduced new risks and challenges, such as safeguarding systems from cyberattacks and protecting consumer’s personal data. Cyberattacks, especially ransomware have shed new light on the importance of privacy and security throughout the banking and financial industry’s digitization efforts. Any organisation affected by cybersecurity attacks must face a twofold legal question. First, whether or not there has been a violation of the legal security requirements? Second, is to determine whether the attack triggers Data Breach Notification to the Data Protection Authority and/or Data Owners. This paper examines the complexity of maintaining security obligations under Indonesian Law (UU ITE, UU PDP, RPP PDP, and other relevant regulations) while also highlighting the common challenges in steering Data Breach Notification, with an enhanced perspective of the European General Data Protection Regulation (EU GDPR) practices. To address the challenges of patchwork data breach notification requirements in Indonesia, this paper proposes a proactive approach by Indonesia’s future Personal Data Protection Authority in creating a one-stop notification model to enable effective data breach incident management and notification.

Keywords: Data Breach Notification, Cybersecurity, Personal Data Protection Authority, Financial Service

##plugins.themes.academic_pro.article.details##

References

  1. Bank Indonesia, “Amendment of Regulation of the Members of the Board of Governors,” Regulation Number 20 of 2023 concerning the Implementation Procedure of Consumer Protection of Bank Indonesia, Article 3 Paragraph 1 Point f.
  2. European Union. “General Data Protection Regulation.” Regulation 2016/679.
  3. Financial Services Authority, Circular Letter 29/SEOJK.03/2022 on Cyber Security and Resilience, Gegevensbeschermingsautoriteit, Case Number -DOS-2019-04867, Paragraph 40, 15.
  4. Indonesia. Electronic Information and Transactions Law. Law No. 11 of 2008. LN.2016/No.251, TLN No. 5952.
  5. Indonesia. Electronic System and Transaction Operation Regulation. Government Regulation No. 71 of 2019.
  6. Indonesia. Personal Data Protection Law. Law No. 27 of 2022. LN.2022/No.196, TLN No.6820.
  7. Indonesia. Personal Data Protection Legislation Bill. Number 27 of 2022.
  8. Indonesia. Presidential Regulation on Protection of Vital Information Infrastructure. Regulation No. 82 of 2022. LN.2022/No.129.
  9. Indonesia. Protection of Personal Data in Electronic Systems Law. Regulation of the Minister of Communication and Information Technology No. 20 of 2016.
  10. Irish Personal Data Protection Commission. Decision on IN-19-9-5.
  11. “PRESS RELEASE BSI Branch, ATM & Mobile Banking Services Have Returned to Normal.” Bank Syariah Indonesia. Accessed February 8, 2024. https://ir.bankbsi.co.id/newsroom/1a92cc8ca2_4364ce956d.pdf.
  12. “PRESS RELEASE BSI President Director: We Apologize and Are Trying to Restore Services,” Bank Syariah Indonesia, accessed February 8, 2024, https://ir.bankbsi.co.id/newsroom/dc70693fac_d7743dac9a.pdf.
  13. “Press Release No. 256/HM/KOMINFO/08/2023 Drafting Implementing Rules, Kominfo Opens Public Participation Through the pdp.id.” Public Relations Bureau of the Ministry of Communication and Information. Accessed February 8 th, 2024. https://www.kominfo.go.id/content/detail/51157/siaran-pers-no-256hmkominfo082023-tentang-susunaturan-pelaksana-kominfo-buka-partisipasi-publik-lewat-laman-pdpid/0/siaran_pers.
  14. Tietosuojavaltuutetun toimisto (Finland Data Protection Authority). Decision of the Deputy Data Protection Commissioner. Case ID Number 2437/161/22, 1.
  15. “83% of organizations paid up in ransomware attacks.” VentureBeat. Accessed February 8 th, 2024. https://venturebeat.com/security/83-of-organizations-paid-up-in-ransomware-attacks/.
  16. “Advocate General Opinion in Case C-340/21, Press Release No. 67/23.” Court of Justice of the European Union. Accessed 8 th February 2024. https://curia.europa.eu/jcms/upload/docs/application/pdf/2023-04/cp230067en.pdf.
  17. “APD/GBA (Belgium)–05/2021,” Paragraph 46. GDPRhub. Accessed February 8, 2024. https://gdprhub.eu/index.php?title=APD/GBA_ (Belgium)_-_05/2021.
  18. “Breach Notification.” Data Protection Commission. Accessed February 8, 2024. https://www.dataprotection.ie/en/organisations/know-yourobligations/breach-notification.
  19. “Case No. 2020-441-4364.” Datalysisnet (Danish Data Protection Authority). Accessed February 8, 2024. https://www.datatilsynet.dk/afgoerelser/afgoerelser/2020/nov/sikkerhedsbrud-hos-zoo.
  20. “Dark Web Profile: LockBit 3.0 Ransomware.” SOCRadar. Accessed February 8 th, 2024. https://socradar.io/dark-web-profile-lockbit-3-0-ransomware/#:~:text=LockBit%203.0%20is%20a%20Ransomware,businesses%20and%20critical%20infrastructure%20organizations.
  21. “Expert Calls Conti Ransomware Gang that Breached BI Dangerous Hackers.” CNN Indonesia. Accessed February 8 th, 2024. https://www.cnnindonesia.com/teknologi/20220120191930-185-749298/ahli-sebutgeng-ransomware-conti-yang-bobol-bi-peretas-berbahaya.
  22. “Guidelines 9/2022 on personal Data Breach Notification under GDPR.” European Data Protection Board. Accessed February 8 th, 2024. https://edpb.europa.eu/system/files/2023-04/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf.
  23. ockBit hackers pocket 15 million BSI customer records, threaten to sell them if negotiations fail.” Merdeka.com. Accessed 8 February 2024. https://www.merdeka.com/teknologi/hacker-lockbit-kantongi-15-jutadata-nasabah-bsi-ancam-dijual-jika-negosiasi-gagal.html.
  24. Meldformulier datalekken.” Autoriteit Persoonsgegevens. Accessed February 8, 2024, https://datalekken.autoriteitpersoonsgegevens.nl/.
  25. “NCCA Hearing Meeting with Commission I The House of Representatives of the Republic of Indonesia.” National Cyber and Crypto Agency. Accessed February 8 th, 2024. https://www.bssn.go.id/rapat-dengar-pendapat-bssn-bersama-komisi-i-dpr/.
  26. “Police Investigate Alleged Hacking of 204 Million Permanent Voter List Data at the General Election Commission.” Metrotvnews.com. Accessed February 9, 2024. https://www.metrotvnews.com/play/bJECaroO-polriusut-dugaan-peretasan-204-juta-data-dpt-di-kpu.
  27. “Stripchat reprimanded for 64.694.953 account breach.” Floort.net. Accessed February 8, 2024. https://floort.net/posts/stripchat_data_breach/.
  28. “The Prolificacy of LockBit Ransomware.” The Hacker News. Accessed February 8, 2024. https://thehackernews.com/2023/03/the-prolificacyof-lockbit-ransomware.html.
  29. Agustini, Pratiwi. “PDP Law will facilitate data exchange with other countries.” Directorate General of Informatics Applications. Accessed 8 February 2024,
  30. Benmalek, Mourad. “Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges.” Journal Internet of Things and Cyber-Physical Systems 4 (January 2024): 186.
  31. Brien, R. O. “Privacy and security: The new European data protection regulation and it’s data breach notification requirements.” Business Information Review, 30 (2016): 81-83.
  32. Burton, Cedric. “Article 32: Security of Processing” in Christopher Kuner the EU General Data Protection Regulation: A Commentary (Oxford: Oxford University Press, 2020): 635-636.
  33. Daigle, Brian and Mahnaz Khan. “The EU General Data Protection Regulation: An Analysis of Enforcement Trends by EU Data Protection Authorities.” Journal of International Commerce & Economics 2020: 9-13.
  34. Darem, Abdulbasit, et al., “Cyber threats classifications and countermeasures in banking and financial sector.” IEEE Access, Vol. 11 (2023): 125139.
  35. Delpiero, Maichle, et al., “Analisis Yuridis Kebijakan Privasi dan Pertanggungjawaban Online Marketplace dalam Pelindungan Data Pribadi Pengguna Pada Kasus Kebocoran Data.” Padjadjaran Law Review, 9, no. 1 (2021): 13-16.
  36. DLA Piper Report. “DLA Piper GDPR Fines and Data Breach Survey: January 2024.” Accessed 8 February 2024. https://www.dlapiper.com/en/insights/publications/2024/01/dla-piper-gdpr-fines-and-data-breachsurvey-january-2024.
  37. Gotay, Anne. “How Ransomware Shakes Up GDPR Compliance.” Sotero. Accessed 8 February 2024. https://www.soterosoft.com/blog/howransomware-shakes-up-gdpr-compliance/.
  38. Greenleaf, Graham. “Global Data Privacy Laws 2021: Despite COV Delays, 145 Laws Show GDPR Dominance.” 169 Privacy Laws and Business International Report, 1, 3-5 (2021).
  39. Hallinan, Dara and Frederik Zuiderveen Borgesius. “Opinions Can Be Incorrect (in our opinion!) On Data Protection Law’s Accuracy Principle.” International Data Privacy Law, 10, no. 1 (2020): 2.
  40. Kosta, Eleni. “Thematic Document: Security of Processing and Data Breach Notification.” European Data Protection Board (November 2023): 8.
  41. Lie, Gunardi, Dylan Aldianza Ramadhan, and Ahmad Redi. “Independent Commission of Personal Data Protection: Quasi-Judicial and Efforts to Create Right to be Forgotten in Indonesia.” Jurnal Yudisial, 15, no. 2 (2022):241-243.
  42. Madnick, Mailhac, Lou. “The EDPB updates the WP29 guidance on personal data breach notification.” Lexology. Accessed 8 February 2024. https://www.lexology.com/library/detail.aspx?g=c95a7003-2cd1-4694-a78c12374adc7254.
  43. Makarim, Edmon., “The Law Against Personal Data Leaks.” Public Relation of Faculty of Law Universitas Indonesia. July 10, 2020. https://law.ui.ac.id/pertanggungjawaban-hukum-terhadap-kebocoran-data-pribadi-olehedmon-makarim/.
  44. McGee, Marianne Kolbasuk, “Irish Authorities Levy GDPR Fine in Centric Health Breach. ”Bank Info Security. Accessed 8 February 2024. https://www.bankinfosecurity.com/irish-authorities-levy-gdpr-fine-in-centrichealth-breach-a-21346.
  45. Meurs, Tom, et al., “Deception in Double Extortion Ransomware Attacks: An Analysis on Profitability and Credibility.” Computers & Security 138 (2024):3.
  46. Multazam, Mochammad Tanzil and Noor Fatimah Mediawati. “Personal Data Collection: Recent Developments in Indonesia.” 2nd Virtual Conference on Social Science in Law, Political Issue and Economic Development (2022): 52.
  47. Nadir, Ibrahim and Taimur Bakshi. “Contemporary Cybercrime: A Taxonomy of Ransomware Threats & Mitigation Techniques.” International Conference on Computing, Mathematics and Engineering Technologies (2018): 5.
  48. Nieuwesteeg, Bernold and Michael Faure. “An Analysis of the Effectiveness of the EU Data Breach Notification Obligation.” Computer & Law Security Review No. 34 (2018): 1237.
  49. Office of the Commissioner for Personal Data Protection Republic of Cyprus. Decision Requesting Excessive Identification Information to Comply to a Subject Access Request by Technius Ltd. Case Ref 11.17.001.010.007. https://drive.google.com/file/d/1nL7rkTZ8BT3srqKXYX2rk18Ib8I8xDXb/view?usp=sharing
  50. Pratama, Erwin. “Negotiation period ends, LockBit reveals BSI data on the Dark Web.” Tempo.co. Accessed 8 February 2024. https://tekno.tempo.co/read/1726219/masa-negosiasi-berakhir-lockbit-ungkap-data-bsi-didark-web.
  51. Respati, Agustinus Rangga, Aprillia Ika. “NCCA Mentions the Potential for Cyber Attacks is Still High, Especially the “Ransomware Type.” Kompas.com. Accessed February 8, 2024. https://money.kompas.com/read/2023/11/15/114406526/bssn-sebut-potensi-serangan-siber-masihtinggi-terutama-jenis-ransomware.
  52. Rosadi, Sinta Dewi. Pembahasan UU Pelindungan Data Pribadi. (Jakarta: Sinar Grafika, Rusmalina, Yunia. “Not Ransomware, BFI Finance Admits to Malware Attack.” Bloomberg Technoz. Accessed 8 February 2024, https://www.bloombergtechnoz.com/detail-news/7300/bukan-ransomware-bfifinance-akui-terkena-serangan-malware.
  53. Ryan, Pierce, et. al., “Dynamics of Targeted Ransomware Negotiation.” IEEE Access, 10 (2022): 32839.
  54. Stuart E. “The Continued Threat to Personal Data: Key Factors Behind the 2023 Increase.” Apple. December 2023. https://www.apple.com/newsroom/pdfs/The-Continued-Threat-to-Personal-Data-Key-FactorsBehind-the-2023-Increase.pdf.