Makassar, Indonesia July 29/ LCPR-RG/- Imagine entrusting your most sensitive financial secrets to a bank, only to later discover that your private information was secretly carried away by a resigning
employee to benefit a rival institution. In today’s highly competitive digital banking
ecosystem, personal data has quickly become the ultimate economic commodity a
new gold mine that generates immense wealth. Unfortunately, the fierce race
to acquire new customers frequently drives financial institutions to disregard the
fundamental ethics of privacy protection, viewing confidential information merely as
a strategic asset to be exploited. The Research titled “From Contractual Breach to Corporate Criminal Liability: Exploitation of Debtor Data by Account Officers in Indonesia ” was published in Justisi Journal accredited by SINTA 3 on 24 April 2026.

One of the most problematic and systematic practices in the Indonesian banking
industry involves the aggressive “poaching” of Account Officers (AOs). Often,
these employees are recruited by rival banks not just for their professional skills, but
specifically for their ability to bring along a lucrative pipeline of existing customers. This alarming trend involves copying, storing, and transferring sensitive identities, credit histories, and financial assets without the explicit, written consent of the actual customers.
Historically, this dangerous exploitation of data was casually brushed off as a mere
labor dispute or a simple breach of an internal confidentiality contract.
However, the legal landscape has radically shifted with the enactment of Indonesia’s
Personal Data Protection (PDP) Law. This vital legislation fundamentally
reconstructs the paradigm: personal data protection is now recognized as an inherent
human right, and violating it is a severe criminal offense. When an AO
unlawfully extracts and commercializes customer data for the benefit of a new
employer, it is no longer just an administrative error; it is a serious crime driven by
intentional economic motives.
Yet, simply punishing the individual employee is not enough to stop this epidemic. We
must confront the intellectual actors—the banking corporations that stimulate these
illegal practices through aggressive, target-driven recruitment policies.
Under the legal doctrine of vicarious liability, a new bank that eagerly accepts an AO
along with their stolen customer database legally qualifies as a “Beneficial Owner” of
the crime. These corporations reap immense long-term profits from the
illicitly acquired data without spending marketing funds. Therefore, to
effectively dismantle this harmful ecosystem, the justice system must implement dual
sanctions: strict imprisonment for the rogue individuals and massive, crippling
administrative fines for the complicit corporations.
Reforming our financial laws to strictly punish corporate data theft explicitly supports
Sustainable Development Goal (SDG) 17: Partnerships for the Goals. Achieving a
safe, equitable, and trustworthy digital economy requires an unyielding, collaborative
partnership between the Financial Services Authority (OJK), law enforcement agencies,
and banking institutions. Together, they must enforce strict legal compliance and build a
transparent financial infrastructure.
Ultimately, a customer’s data is never a corporate bargaining chip. By enforcing strict
corporate criminal liability, Indonesia can ensure that citizen privacy is fiercely
protected, proving that trust must always remain more valuable than profit.
Reference
DOI:
https://doi.org/10.33506/js.v12i2.5298
Contact:
Afif Muhni, S.H., M.H.
Afif.Muhni@unhas.ac.id




