Kessy Dealova
Cyber Security Engineering, Politeknik Negeri Batam

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Mapping Compliance–Maturity Gaps in EdTech Personal Data Security: Integrating the PDP Law and KAMI Index 5.0 Ocha Oktafia; Nelmiawati Nelmiawati; Putri Hening Graha; Kessy Dealova
Journal of Applied Informatics and Computing Vol. 10 No. 4 (2026): August 2026
Publisher : Politeknik Negeri Batam

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30871/jaic.v10i4.13447

Abstract

The rapid post-pandemic growth of Educational Technology (EdTech) platforms in Indonesia is not always accompanied by personal data security readiness, despite the high compliance demands mandated by Law Number 27 of 2022 concerning Personal Data Protection (PDP Law). Previous studies utilizing the KAMI Index generally assessed technical maturity separately from legal frameworks, leaving a gap in understanding how regulatory compliance correlates with technical maturity within a single entity. This study aims to evaluate the information security maturity level and legal compliance of PT XYZ's EdTech platform, while simultaneously mapping the connection between the PDP Law requirements and the assessment areas of KAMI Index 5.0. This research employs a qualitative case study approach. Data were collected through questionnaires based on the KAMI Index 5.0 instrument and PDP Law articles, completed by three key respondents—the CEO, CTO, and VP of Information Security—and subsequently validated through interviews and verification of supporting documents. The results reveal a significant gap: procedural compliance with the PDP Law is relatively high (28 out of 36 articles fully implemented), yet the KAMI Index maturity level falls into the "Inadequate" (Tidak Layak) category with a final score of 222. The system is notably weak in risk management and personal data protection areas (Level I+). These findings emphasize that procedural compliance does not equate to holistic security maturity. This research contributes by providing a legal-technical gap mapping alongside recommendations based on ISO/IEC 27002:2022, which can be adopted by other EdTech organizations.