Technology & Gadgets

Digital Transactions Security Requires Independent Verification to Ensure Legal Validity and Consumer Protection

In an era where the Indonesian digital economy is expanding at an unprecedented pace, the integrity of online transactions has become a critical focal point for regulators, legal experts, and cybersecurity professionals. During a recent high-level discussion titled "The Forum: Increasingly Digital, Who Guarantees Our Security?", industry leaders reached a consensus that internal verification systems—often referred to as "self-claiming"—are no longer sufficient to safeguard users. The discourse highlighted that for digital transactions to hold weight in a court of law, they must be underpinned by independent third-party verification through Electronic Certification Providers (PSrE) and Certified Electronic Signatures (TTE).

The Fragility of Self-Claimed Security

The fundamental shift in the digital landscape requires a departure from traditional, face-to-face identity verification. Edmon Makarim, a former Dean of the Faculty of Law at the University of Indonesia, emphasized the legal vulnerabilities inherent in the current reliance on platform-based verification. Under Article 15 of the Law on Electronic Information and Transactions (UU ITE), the security of an electronic system lacks the necessary legal standing if it relies solely on the internal assertions of the service provider.

"When parties in a digital transaction do not know each other, the old ways of verifying identity fail," Makarim stated. He argued that the legal legitimacy of a contract or transaction requires an impartial "referee." By utilizing asymmetric cryptography managed by a certified PSrE, the digital signature gains the status of a legally binding document that can withstand judicial scrutiny. Without this, consumers and businesses alike remain exposed to the risks of repudiation—where a party denies their involvement in a transaction—and legal ambiguity in the event of fraud.

The Technical Imperative: Multi-Layered Authentication

The technical challenges of digital security extend beyond simple password protocols. Yudho Giri Sucahyo, a prominent information technology expert, underscored that cybersecurity is not merely a policy issue but a technical one. The transition from desktop to mobile environments has introduced significant security gaps.

"Trust in the cyber realm must be proven technically," Sucahyo explained. He advocated for a multi-layered authentication framework that incorporates not only passwords and CAPTCHA but also biometric scanning and, crucially, certified electronic signatures. The risk of "account takeover" (ATO) remains one of the most prevalent threats in the current digital ecosystem. When a system fails to recognize the legitimate owner of an identity on a new or unrecognized device, it opens a window for malicious actors to hijack sessions, access financial data, and execute illicit transactions. This vulnerability is exacerbated by platforms that prioritize user convenience over rigorous security protocols.

The Cost of Convenience: Pinjol and Data Vulnerability

The consequences of lax verification policies are not merely theoretical; they have tangible impacts on the financial well-being of the Indonesian public. Zico L. Djagardo, an advocate and victim of data misuse, provided a harrowing account of how unregulated verification processes can dismantle a person’s financial standing. After his personal data was stolen, Djagardo found himself linked to fictitious financial transactions, severely damaging his creditworthiness.

His investigation revealed a disturbing trend: several peer-to-peer (P2P) lending platforms, colloquially known as pinjol, consciously opted against integrating with PSrE or utilizing TTE systems. The primary motivation, according to Djagardo, was the reduction of operational costs. By bypassing independent verification, these platforms expose their users to identity theft while simultaneously making it nearly impossible for victims to clear their names, as the platforms lack the cryptographic proof required to distinguish between legitimate borrowers and fraudulent impersonators.

Djagardo is now lobbying for more granular regulations regarding the use of electronic signatures. He posits that the intervention of the Constitutional Court (MK), which has mandated the development of technical implementation rules for data protection, should be treated as a blueprint for mandatory PSrE adoption. By positioning the PSrE as an independent arbiter, the government can ensure that disputes between consumers and digital platforms are resolved based on objective, immutable digital evidence.

Legislative Evolution: Revising PP 71/2019

The government has acknowledged the urgency of these concerns. Aulia, representing the Directorate of Digital Space Supervision Strategy and Policy at the Ministry of Communication and Digital (Komdigi), confirmed that the state is actively working on a revision of Government Regulation (PP) Number 71 of 2019.

This legislative update is expected to address the critical gaps in the current regulatory framework. The proposed changes include specific mandates for handling high-risk transactions and the formal implementation of a national digital identity system. By standardizing the requirements for electronic certification, the government aims to provide a more robust legal umbrella for both the digital industry and the citizenry.

Contextualizing the Digital Risk Landscape

To understand the gravity of this shift, one must consider the trajectory of Indonesia’s digital economy. According to recent data from the E-Conomy SEA report, Indonesia’s internet economy is projected to continue its upward trend, with digital payments and e-commerce serving as primary drivers. However, as the volume of transactions increases, so does the sophistication of cybercrime.

  • 2019: The enactment of PP 71/2019 provided a foundational structure for electronic system operators, but rapid technological advancements soon outpaced the regulation.
  • 2022-2023: A surge in reports of unauthorized P2P lending applications highlighted the lack of enforcement regarding identity verification.
  • 2024: The Ministry of Communication and Digital signaled a shift toward stricter oversight, prioritizing the "multiple protection" of personal data as requested by judicial mandates.

The correlation between the lack of independent certification and the rise in financial fraud is clear. Platforms that prioritize rapid onboarding at the expense of authentication create "weak links" in the national financial ecosystem. When these systems are compromised, the victim often lacks the necessary tools to prove their innocence, leading to prolonged legal battles and financial exclusion.

Implications for the Future

The push for mandatory PSrE and TTE certification is not merely a bureaucratic hurdle; it is a structural necessity for a maturing digital economy. If implemented correctly, these measures will create a "verifiable trust" environment. In this environment, a digital signature will be equivalent to a wet-ink signature witnessed by a notary, effectively mitigating the risk of identity theft and platform-side fraud.

However, the transition poses a challenge for small and medium-sized enterprises (SMEs) that may struggle with the associated costs of adopting high-level security infrastructure. The government’s role in the upcoming revision of PP 71/2019 will be to balance the need for rigorous security with the accessibility of digital services. Providing subsidies or simplified access to certified PSrE services could be a viable path forward for smaller platforms.

As Indonesia navigates the complexities of the digital age, the discourse at "The Forum" serves as a wake-up call. Security is no longer a peripheral concern that can be managed through internal audits. It is a fundamental requirement for the functioning of a modern, democratic, and secure digital society. By moving toward an ecosystem where third-party verification is the standard, Indonesia is positioning itself to be a more resilient player in the global digital economy, ensuring that as its citizens become more digital, they also become significantly more secure.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button