This study examines the normative gap between the consumer protection provisions of Indonesia's Financial Services Authority (OJK) under Articles 31– 32 of Law No. 21 of 2011 and the enforcement of corporate criminal liability for the misuse of customers' personal data under Articles 65–70 of Law No. 27 of 2022 on Personal Data Protection (UU PDP). It finds that OJK's administrative sanctions are not yet effectively integrated with the PDP Law. Drawing on the doctrines of vicarious liability and agency, the study argues that fintech corporations should bear criminal responsibility as primary data controllers. It recommends adopting strict liability provisions and optimizing Supreme Court Regulation No. 13 of 2016 to strengthen consumer protection.
Copyrights © 2026