Scholars International Journal of Law, Crime and Justice (SIJLCJ)
Volume-9 | Issue-10 | 309-314
Original Research Article
Legal Concept of Strict Liability for Banks in the Misuse of Customer Personal Data
Zulfi Diane Zaini, Efendi Putra
Published : Oct. 1, 2026
Abstract
Leaks and misuse of banking customer personal data in Indonesia are increasingly common along with the acceleration of digital transformation. Although Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) has been passed, the burden of proving fault still often presents a challenge for customers as the injured party. This study aims to analyze the urgency of implementing the principle of strict liability as a legal protection instrument for customers in cases of personal data misuse by banking institutions. The research method used is a normative juridical approach with a statutory approach and a conceptual approach. The results show that the application of the principle of fault liability in the highly regulated banking industry is no longer relevant due to information asymmetry and the complexity of information technology systems. Adopting the principle of strict liability holds banks accountable for any failure to protect data without requiring customers to prove fault on their part. The implementation of this principle is expected to encourage banking institutions to maximize cybersecurity standards while providing legal certainty and redress for customers more effectively and efficiently.