Enhancing Data Protection in Banking: Implementation and Evaluation of an AI-Driven System

  • Sugianto Sugianto Swiss German University
  • Mohammad A Soetomo Swiss German University
  • Heru Ipung Swiss German University
Keywords: Artificial Intelligence (AI), Data Protection, Record of Processing Activities (RoPA), Data Protection Impact Assessment (DPIA), Personal Data Protection Law (UU PDP).

Abstract

This research aims to implement an AI-driven system for managing Records of Processing Activities (RoPA) and Data Protection Impact Assessments (DPIA) at Bank XYZ to comply with Indonesias Personal Data Protection Law (PDPL). The research uses a qualitative approach, incorporating case studies and interviews to investigate the AI systems impact on improving compliance, efficiency, and data security within the banking sector. Initial results show significant improvements in the accuracy and speed of processing personal data protection documents. The AI system simplifies the management of RoPA and DPIA and promotes a robust compliance environment by adhering to national and international data protection standards. It is recommended to continually advance AI and provide ongoing training to address emerging data security and privacy challenges.

Downloads

Download data is not yet available.

References

Bank for International Settlements (2016) ‘Basel Committee on Banking Supervision’. Available at: https://www.bis.org/bcbs/publ/d355.pdf (Accessed: 2 January 2025).
Bank Indonesia (2024) Bank Indonesia.
Basel Committee on Banking Supervision (2003) ‘Sound Practices for the Management and Supervision of Operational Risk’. Available at: https://www.bis.org/publ/bcbs86.pdf.
Boehm, B.W. (1988) ‘A Spiral Model of Software Development and Enhancement’, ACM SIGSOFT Software Engineering Notes, 11(4), pp. 14–24.
Booch, G. (1991) Object-Oriented Analysis and Design with Applications. Addison-Wesley.
BSSN (2024) ‘BSSN Identifikasi Pusat Data Nasional Sementara Diserang Ransomware’. Available at: https://www.bssn.go.id/bssn-identifikasi-pusat-data-nasional-sementara-diserang-ransomware/ (Accessed: 29 June 2024).
BSSN (Badan Siber dan Sandi Negara) (2020) ‘Cybersecurity Report 2020’. Available at: https://cloud.bssn.go.id/s/ZSdfebRTKW7p8nW#pdfviewer.
BSSN (Badan Siber dan Sandi Negara) (2021) ‘Cybersecurity Report 2021’. Available at: https://cloud.bssn.go.id/s/Lyw8E4LxwNiJoNw.
BSSN (Badan Siber dan Sandi Negara) (2023) ‘Lanskap Keamanan Siber Indonesia 2023’. Available at: https://www.bssn.go.id/wp-content/uploads/2024/03/Lanskap-Keamanan-Siber-Indonesia-2023.pdf.
CCPA (2021) ‘California Consumer Privacy Act (CCPA)— State of California—Department of Justice.’ Available at: https://oag.ca.gov/privacy/ccpa (Accessed: 25 November 2023).
Chakrabarti, D., Goswami, A. and Basu, R. (2018) ‘Use of Artificial Intelligence to Analyze Risk in Legal Documents for a Better Decision Support’, in TENCON 2018 - IEEE Region 10 Conference, pp. 1123–1127. Available at: https://doi.org/10.1109/TENCON.2018.8650372.
CNN (2023) https://www.cnnindonesia.com/teknologi/20230513093401-185-949046/ransomware-lockbit-30-klaim-lumpuhkan-bsi-dan-curi-data-pengguna.
Fitzgerald, B. et al. (2013) ‘Hybrid Agile-Waterfall Methods in Regulated Environments’, Journal of Systems and Software, 98, pp. 87–95.
GDPR (2016) ‘General Data Protection Regulation (GDPR)’. Available at: https://gdpr-info.eu/ (Accessed: 9 November 2023).
ID-SIRTII (2024) ‘Laporan Hasil Monitoring’. Available at: https://www.idsirtii.or.id/halaman/tentang/laporan-hasil-monitoring.html.
Kominfo (2024) https://www.kominfo.go.id/.
(Kominfo), M.I.T. of C. (2022) ‘Undang-Undang Perlindungan Data Pribadi (UU PDP no 27)’.
Koto, F. et al. (2020) ‘IndoLEM and IndoBERT: A Benchmark Dataset and Pre-trained Language Model for Indonesian NLP’, in COLING, pp. 757–770. Available at: https://aclanthology.org/2020.coling-main.66.pdf.
Lee, P.-L., Lye, C.-T. and Lee, C. (2022) ‘Is bank risk appetite relevant to bank default in times of Covid-19?’, Central Bank Review, 22(3), pp. 109–117. Available at: https://doi.org/https://doi.org/10.1016/j.cbrev.2022.08.003.
Martin, R.C. (2008) Clean Code: A Handbook of Agile Software Craftsmanship. Prentice Hall.
Meyer, B. (1997) Object-Oriented Software Construction. Prentice Hall.
Mutiasari, A. (2020) ‘PERKEMBANGAN INDUSTRI PERBANKAN DI ERA DIGITAL’, JURNAL EKONOMI BISNIS DAN KEWIRAUSAHAAN, 9, p. 32. Available at: https://doi.org/10.47942/iab.v9i2.541.
Nicholas Hills (2023) ‘Financial Conduct Authority, Enforcement and Market Oversight Division’. Available at: https://www.fca.org.uk/publication/final-notices/equifax-limited-2023.pdf (Accessed: 14 January 2025).
of Law, M. and Rights, H. (2022) ‘Draft Peraturan Pemerintah (PP) on the Implementation of UU PDP’.
OJK (2024a) ‘Implementasi Kerangka Basel di Indonesia’. Available at: https://www.ojk.go.id/id/kanal/perbankan/implementasi-basel/Pages/International-Financial-Reports.aspx (Accessed: 2 January 2025).
OJK (2024b) ‘Keanggotaan OJK di BCBS’. Available at: https://www.ojk.go.id/id/kanal/perbankan/implementasi-basel/Pages/Quantitative-Impacts-Study.aspx (Accessed: 2 January 2025).
(OJK), O.J.K. (2022) ‘Penyelenggaraan Teknologi Informasi di Lingkungan Perbankan’. Available at: https://www.ojk.go.id.
(OJK), O.J.K. (2023) ‘Penilaian Tingkat Maturitas Digital Bank Umum’. Available at: https://www.ojk.go.id.
Onan, F. (2022) ‘Multi-Label Classification with BERT in Compliance’, Journal of AI Applications, 45, pp. 123–138.
Pandey, M., Sharma, N. and Singh, P. (2023) ‘AI-based Integrated Approach for the Development of Intelligent Document Management System (IDMS)’, in Procedia Computer Science, pp. 123–130.
PIPL (2021) ‘The PRC Personal Information Protection Law.’ Available at: https://www.china-briefing.com/news/the-prc-personalinformation- protection-law-final-a-full-translation/ (Accessed: 25 November 2023).
Pressman, R.S. (2005) Software Engineering: A Practitioner’s Approach. McGraw-Hill.
Royce, W.W. (1970) ‘Managing the Development of Large Software Systems’, Proceedings of IEEE WESCON, pp. 1–9.
Subburayan, B., Ajekwe, C. and Nakitende, M. (2023) ‘Accounting Fraud and Bankruptcy: The Case of Wirecard AG’, in Theory and Practice of Illegitimate Finance. IGI Global, pp. 222–244. Available at: https://doi.org/10.4018/979-8-3693-1190-5.ch012.
U.S. Department of Justice (2020) ‘Wells Fargo Agrees to Pay $3 Billion to Resolve Criminal and Civil Investigations into Sales Practices Involving the Opening of Millions of Accounts without Customer Authorization’. Available at: https://www.justice.gov/opa/pr/wells-fargo-agrees-pay-3-billion-resolve-criminal-and-civil-investigations-sales-practices (Accessed: 14 January 2025).
Yusuf (2022) ‘Menkominfo: RUU PDP Disahkan, Kominfo Awasi Tata Kelola Data Pribadi PSE’. Available at: https://aptika.kominfo.go.id/2022/09/menkominfo-uu-pdp-disahkan-kominfo-awasi-tata-kelola-data-pribadi-pse/ (Accessed: 9 November 2023).
Wei, J., Bosma, M., Zhao, V., Guu, K., Yu, A., Lester, B., Du, N., Dai, A. and Le, Q. (2022). Published as a conference paper at ICLR 2022 FINETUNED LANGUAGE MODELS ARE ZERO-SHOT LEARNERS. [online] Available at: https://arxiv.org/pdf/2109.01652.
Brown, T., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., Askell, A., Agarwal, S., Herbert-Voss, A., Krueger, G., Henighan, T., Child, R., Ramesh, A., Ziegler, D., Wu, J., Winter, C. and Hesse, C. (2020). Language Models are Few-Shot Learners. [online] Available at: https://arxiv.org/pdf/2005.14165.
Published
2025-11-25