Journal of Law and Legal Reform
Vol. 7 No. 3 (2026): July, 2026

Regulatory Sandbox for Ex-Ante Data Protection in the Digital Rupiah (CBDC) Pilot: A Doctrinal Comparison

Wardah Yuspin (Faculty of Law and Political Science, Universitas Muhammadiyah Surakarta, Surakarta, Indonesia)
Arief Budiono (Faculty of Law and Political Science, Universitas Muhammadiyah Surakarta, Surakarta, Indonesia)
Turdialiev Mukhammad Ali Polatjon ogli (Tashkent State University of Law, Tashkent, Uzbekistan)
Jompon Pitaksantayothin (Hankuk University of Foreign Studies, Seoul, South Korea)
Naeem Rakha Allah (Tashkent State University of Law, Tashkent, Uzbekistan)



Article Info

Publish Date
13 Jul 2026

Abstract

The transformation of digital payments has prompted central banks to explore Central Bank Digital Currency (CBDC) as a new form of monetary infrastructure. However, CBDC is not merely a payment instrument; it also establishes a data processing regime, as transactions can be recorded, traced, and systematically processed. Existing studies on CBDC and privacy generally discuss design options or anonymity, but they rarely explain how personal data protection compliance should be tested before a CBDC pilot is expanded. This article addresses that gap by examining how the Digital Rupiah pilot can be designed as an ex-ante mechanism for testing compliance with Indonesia’s Personal Data Protection Law. The novelty of this article lies in its proposal of a rights-based regulatory sandbox model that integrates CBDC architecture, tiered KYC, data minimization, access governance, and remedial mechanisms into a single operational compliance framework. Using a normative legal approach and comparative method, this article interprets Indonesia’s PDP Law. It compares it with Uzbekistan’s data protection framework as an analytical mirror for assessing how processing controls and architectural requirements influence CBDC design. The article contributes to scientific knowledge by formulating a norm-to-control sandbox model that translates data protection principles into testable indicators, including purpose limitation, role-based access controls, audit trails, retention limits, and go/no-go compliance criteria. The findings show that the legitimacy of the Digital Rupiah pilot should not be measured only by technical performance or payment efficiency, but also by whether the sandbox can prove that data processing is lawful, proportionate, transparent, and auditable before wider implementation.

Copyrights © 2026






Journal Info

Abbrev

jllr

Publisher

Subject

Law, Crime, Criminology & Criminal Justice

Description

The Journal seeks to disseminate information and views on matters relating to law reform, including developments in case and statute law, as well as proposals for law reform, be they from formal law reform bodies or from other institutions or ...