Indonesia has brought convenience to financial transactions, but it has also increased the risk of customer personal data leaks, particularly because banks now rely on cyber security systems and artificial intelligence in Know Your Customer procedures, biometric authentication, and credit scoring. This phenomenon raises concerns about the weak protection of privacy rights and the security of customers’ financial data. This study aims to analyse the forms of legal protection provided to customers against personal data leaks and the criminal law policy governing cybercrime committed through artificial intelligence. This research is normative legal research employing statutory, conceptual, and comparative approaches, with legal materials collected through a literature study of legislation, legal doctrine, and reported cases of data breaches in the national banking sector. The results show that although a national legal framework has been established through Law Number 27 of 2022 concerning Personal Data Protection, the Banking Law, and the regulations of the Financial Services Authority and Bank Indonesia, its implementation is still obstructed by weak law enforcement, the absence of technical benchmarks for data protection by design and for explainable artificial intelligence, unprepared digital banking infrastructure, and low customer awareness. Criminal law policy has likewise not accommodated artificial intelligence as a means of committing crime, which creates a legal vacuum. This study therefore recommends a rebuttable presumption of negligence for banks, explainable artificial intelligence compliance benchmarks, and a lex specialis governing artificial intelligence-based cybercrime.
Copyrights © 2026