PERTANGGUNGJAWABAN PIDANA PERBANKAN DALAM PERLINDUNGAN DATA NASABAH AKIBAT TINDAK PIDANA CARDING

Authors

  • Muhammad Chilman Abdillah Universitas Negeri Surabaya
  • Vita Mahardhika

Keywords:

Corporate Criminal Liability, Strict Liability, Normative Vagueness, Personal Data Protection, Carding

Abstract

Carding offences that exploit leaked banking-customer data continue to rise alongside the acceleration of financial-service digitalisation in Indonesia. A normative problem arises because the phrase "intentionally" in Article 67 of Law Number 27 of 2022 on Personal Data Protection doctrinally covers only dolus and does not accommodate culpa, leaving banks whose negligence enables third-party carding within a criminal-law grey zone. This study analyses that normative vagueness and examines the relevance of strict liability theory as a normative solution through a shift in the standard of mens rea from dolus to culpa objectiva. A normative juridical method is employed, using statutory, conceptual, and case approaches, with the Surabaya High Court Decision Number 845/PID.SUS/2020/PT SBY as the point of entry for analysis. Two findings emerge. First, normative vagueness exists in Article 67 of the Personal Data Protection Law and Article 47A of Law Number 10 of 1998 on Banking, such that the penal mechanism fails to reach corporate negligence by banks. Second, strict liability theory is relevant as a de lege ferenda solution because it shifts the burden of proof from subjective intent to objective failure to meet data-protection duties, subject to limits of causation, force majeure, and customer contributory negligence.

Downloads

Published

2026-07-21
Abstract views: 75 , PDF Downloads: 6

Similar Articles

<< < 1 2 3 4 5 6 7 8 9 10 > >> 

You may also start an advanced similarity search for this article.