Insights
Data Confidentiality in Financial Sector Professional Engagements: Shared but Differentiated Responsibility
Bellina Christy, Raditya Gerardi SimarmataIntroduction
Supporting professions in the financial services sector, including public accountants, actuaries, public appraisers, notaries, legal consultants, and other professions designated by the Financial Services Authority (OJK), routinely access information that is not publicly available. Their work may involve customer identities, transaction records, financial statements, beneficial ownership information, legal disputes, internal controls, and business strategies.
The involvement of an external professional does not, however, automatically transfer confidentiality and data-protection risks. The service recipient typically selects the professional, determines the purpose of the engagement, decides what information is disclosed, and controls how the resulting work is used.
Accordingly, POJK No. 5 of 2025 concerning Supporting Professions in the Financial Services Sector (POJK 5/2025) and Law No. 27 of 2022 concerning Personal Data Protection (PDP Law) apply together: POJK 5/2025 establishes sector-specific confidentiality obligations, while the PDP Law regulates the processing of personal data and allocates responsibility according to each party's actual role.
Confidentiality under POJK 5/2025
Article 17 of POJK 5/2025 requires supporting professionals to remain independent, objective, and professional, maintain the confidentiality of data and information obtained in providing services, and comply with applicable professional, quality-control, and ethical standards.
Confidentiality is also supported by regulatory sanctions. A breach of confidentiality or failure to comply with professional and quality-control standards may result in suspension of registration for up to one year and an administrative fine of up to IDR 5 billion. Repeated suspension may lead to cancellation of registration. Accordingly, confidentiality is not merely an ethical obligation but may directly affect a professional's ability to operate in the financial services sector.
POJK 5/2025 also permits or requires disclosure to OJK in certain circumstances. Such disclosure should remain limited to what is legally required or specifically requested and should be handled securely and appropriately documented.
Allocation of Roles under the PDP Law
The PDP Law distinguishes between a Personal Data Controller, which determines the purposes and means of processing, and a Personal Data Processor, which processes personal data on behalf of a controller. These roles are determined by the parties' actual functions rather than contractual labels.
The recipient must therefore ensure that the disclosure is supported by an appropriate lawful basis under Article 20 of the PDP Law. A supporting professional will generally act as a processor where it processes personal data solely based on the recipient's documented instructions. However, where professional or statutory obligations require the professional to independently determine how certain personal data is reviewed, retained, or disclosed, it may act as an independent controller.
Article 51 of the PDP Law provides an important basis for allocating responsibility: processing conducted by a processor based on the controller's instructions remains the controller's responsibility, while responsibility may shift to the processor where it acts beyond those instructions.
Duties of the Service Recipient
A confidentiality clause should not be treated as a complete transfer of legal risk. Before disclosing information, the recipient should assess whether the data is necessary, relevant, and proportionate to the professional purpose. Providing an entire customer database where a limited sample would suffice, for example, may be inconsistent with the PDP Law's requirements concerning lawful, specific, transparent, and purpose-limited processing.
The recipient should conduct due diligence on the professional's governance and security arrangements and maintain appropriate records of the data disclosed, its legal basis, authorized recipients, and retention periods.
Where the engagement involves high-risk processing, Article 34 may require a data-protection impact assessment. The professional should provide sufficient information regarding its processing activities, systems, and safeguards to support the assessment.
Duties of the Supporting Professional
Supporting professionals must use information only for the agreed and lawful professional purpose. Access should be restricted on a need-to-know basis, client files should be appropriately segregated, secure channels should be used for data transmission, and relevant processing activities should be documented.
Professional independence does not eliminate data-protection responsibilities. Where a professional independently determines which records must be examined or retained, it should identify the applicable lawful basis and purpose for such processing. Information retained for professional purposes should not be repurposed for unrelated activities without an appropriate lawful basis.
Contractual Allocation of Responsibilities
The engagement agreement should clearly define the parties' roles, permitted purposes, data categories, access rights, security measures, subcontracting, retention, return or destruction of data, and incident-reporting obligations.
Contractual allocation does not replace statutory allocation. A clause describing the professional as a processor will not be determinative where its actual conduct shows that it independently determines the purposes or essential means of a particular processing activity.
Breach Response and Liability
Article 46 of the PDP Law requires notification to affected data subjects and the competent institution no later than 3 x 24 hours after a personal-data protection failure. The engagement agreement should therefore require the professional to report suspected incidents internally within a shorter period and assist with containment, evidence preservation, and notification.
Liability depends on the parties' actual roles and conduct, including who determined the processing purpose, controlled access, or acted outside documented instructions.
Conclusion
POJK 5/2025 establishes sector-specific confidentiality obligations, while the PDP Law allocates personal-data responsibilities according to the parties' actual roles.
The resulting framework is one of shared but differentiated responsibility: the service recipient remains responsible for lawful and proportionate disclosure and oversight, while the supporting professional remains responsible for confidentiality, security, and processing within lawful instructions.
This article is intended for general informational purposes only and does not constitute legal advice. For legal assistance or inquiries specific to your situation, please contact us at info@adplaws.com.

_1786357425.jpg)