This Author published in this journals
All Journal Rechtsvinding
Iwan Erar Joesoef
niversitas Pembangunan Nasional "Veteran" Jakarta

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Platform Liability as a Personal Data Controller for The Processing of Emergency Contact Data in Fintech Lending Agreements (A Study on The Kredit Pintar Platform) Raka Haikal Anfasya; Andriyanto Adhi Nugroho; Iwan Erar Joesoef
Rechtsvinding Vol. 4 No. 2 (2026)
Publisher : Civiliza Publishing

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59525/rechtsvinding.1856

Abstract

The development of financial technology lending (fintech lending) drives service providers to collect and process users' personal data, including the personal data of emergency contacts as part of loan application requirements. In practice, the processing of emergency contact personal data is conducted based on standard clauses that require users to state that they have obtained consent from the party registered as an emergency contact and transfer certain liabilities to the user. This condition raises issues regarding the validity of personal data processing and the platform's liability as a Personal Data Controller under Law Number 27 of 2022 concerning Personal Data Protection. This research aims to analyze the validity of the processing of emergency contact personal data in the fintech lending agreement of the Kredit Pintar Platform based on Law Number 27 of 2022 concerning Personal Data Protection and to analyze the platform's liability as a Personal Data Controller for the processing of emergency contact personal data. This research utilizes a normative legal research method with a statute approach, a conceptual approach, and a contract study approach. Legal materials were obtained through a literature study and analyzed qualitatively using a prescriptive method. The results of the research indicate that the validity of processing emergency contact personal data is insufficient if it is merely based on the user's statement of having obtained consent from the emergency contact, but must satisfy a lawful basis for processing as well as the principles of personal data protection as regulated in the Personal Data Protection Law. Furthermore, the platform as a Personal Data Controller retains legal liability for the processing of emergency contact personal data; thus, clauses transferring liability to the user do not eliminate the platform's legal obligations to protect the rights of the Personal Data Subject.