This article examines the legal liability of securities companies for ransomware attacks that result in the misuse of investors’ personal data in Indonesia. Using normative legal research with statute, conceptual, and case approaches, this study shows that the relevant legal framework is formed by the Capital Market Law, the Personal Data Protection Law, the Electronic Information and Transactions Law as amended by Law No. 1 of 2024, the Financial Sector Development and Strengthening Law, and OJK consumer protection regulations. The research gap lies in the absence of a focused analysis of securities companies’ accountability through the doctrines of duty of care, corporate negligence, and cyber liability in the capital market context. This article finds that liability may arise contractually, in tort, and administratively when a securities company fails to implement reasonable security measures, supervision, and incident response. Stronger harmonization of sectoral rules, explicit breach notification standards, and risk-based security obligations are therefore needed to protect investors more effectively.
Copyrights © 2026