JOURNAL OF APPLIED INFORMATICS AND COMPUTING
Vol. 10 No. 4 (2026): August 2026

Mapping Compliance–Maturity Gaps in EdTech Personal Data Security: Integrating the PDP Law and KAMI Index 5.0

Ocha Oktafia (Cyber Security Engineering, Politeknik Negeri Batam)
Nelmiawati Nelmiawati (Cyber Security Engineering, Politeknik Negeri Batam)
Putri Hening Graha (Public Policy, National University of Singapore)
Kessy Dealova (Cyber Security Engineering, Politeknik Negeri Batam)



Article Info

Publish Date
12 Aug 2026

Abstract

The rapid post-pandemic growth of Educational Technology (EdTech) platforms in Indonesia is not always accompanied by personal data security readiness, despite the high compliance demands mandated by Law Number 27 of 2022 concerning Personal Data Protection (PDP Law). Previous studies utilizing the KAMI Index generally assessed technical maturity separately from legal frameworks, leaving a gap in understanding how regulatory compliance correlates with technical maturity within a single entity. This study aims to evaluate the information security maturity level and legal compliance of PT XYZ's EdTech platform, while simultaneously mapping the connection between the PDP Law requirements and the assessment areas of KAMI Index 5.0. This research employs a qualitative case study approach. Data were collected through questionnaires based on the KAMI Index 5.0 instrument and PDP Law articles, completed by three key respondents—the CEO, CTO, and VP of Information Security—and subsequently validated through interviews and verification of supporting documents. The results reveal a significant gap: procedural compliance with the PDP Law is relatively high (28 out of 36 articles fully implemented), yet the KAMI Index maturity level falls into the "Inadequate" (Tidak Layak) category with a final score of 222. The system is notably weak in risk management and personal data protection areas (Level I+). These findings emphasize that procedural compliance does not equate to holistic security maturity. This research contributes by providing a legal-technical gap mapping alongside recommendations based on ISO/IEC 27002:2022, which can be adopted by other EdTech organizations.

Copyrights © 2026






Journal Info

Abbrev

JAIC

Publisher

Subject

Computer Science & IT

Description

Journal of Applied Informatics and Computing (JAIC) Volume 2, Nomor 1, Juli 2018. Berisi tulisan yang diangkat dari hasil penelitian di bidang Teknologi Informatika dan Komputer Terapan dengan e-ISSN: 2548-9828. Terdapat 3 artikel yang telah ditelaah secara substansial oleh tim editorial dan ...