Legal Protection Analysis of Personal Data Breaches in Shopee Paylater Consumer Loan Transactions

Authors

  • Dewi Noviyanti Institut Informatika dan Bisnis Darmajaya Author
  • Yuniwati Institut Informatika dan Bisnis Darmajaya Author
  • Suratno Institut Informatika dan Bisnis Darmajaya Author

DOI:

https://doi.org/10.56347/jle.v4i1.240

Keywords:

Online Loans, Shopee Paylater, Legal Protection

Abstract

The widespread use of personal information in pay-later-based loan applications services reflects the vulnerability of digital security systems implemented by technology companies in Indonesia. Recently, several Shopee users reported being victims of such cases, claiming they never activated the paylater feature, yet their bank loan applications were declined due to poor credit records linked to SPayLater usage. While services like Shopee's SPayLater offer convenience, they also increase the risks of default and data breaches. Incidents such as improper debt collection practices and unauthorized access to ShopeePay balance reveal flaws in the platform's data protection and security measures. This underscores the need for in-depth research to strengthen legal safeguards for consumer personal data in Shopee's digital transactions. Findings indicate that SPayLater, as the data controller, holds the responsibility to collect, process, and protect consumer information throughout its lifecycle. Nevertheless, Shopee is perceived to have fallen short in fulfilling this duty, resulting in consumers suffering losses from unauthorized use of their data for loan applications. This situation highlights the urgency for more robust legal protections—both internally and externally to guarantee the protection of users' personal information. This research uses a normative legal research type with a descriptive research type. The problem approach uses a statutory approach with a case approach.

Author Biographies

  • Dewi Noviyanti, Institut Informatika dan Bisnis Darmajaya

    Business Law Study Program, Institut Informatika dan Bisnis Darmajaya, Bandar Lampung City, Lampung Province, Indonesia

  • Yuniwati, Institut Informatika dan Bisnis Darmajaya

    Business Law Study Program, Institut Informatika dan Bisnis Darmajaya, Bandar Lampung City, Lampung Province, Indonesia

  • Suratno, Institut Informatika dan Bisnis Darmajaya

    Business Law Study Program, Institut Informatika dan Bisnis Darmajaya, Bandar Lampung City, Lampung Province, Indonesia

References

Agus Sudibyo. (2019). Liberation and control. Gramedia Pustaka Utama.

Ashofa, B. (2004). Legal research methods. PT Rineka Cipta.

Benuf, C., Mahmudah, S., & Priyono, E. A. (2019). Legal Protection of Financial Technology Consumer Data Security in Indonesia. Legal Reflections: Journal of Legal Sciences, 3(2), 145-160.

CNIL. (2021, July 30). Amazon fined €746M for GDPR violations. European Data Protection Board. https://edpb.europa.eu/news/national-news/2021/amazon-fined-eu746m-gdpr-violations_en

European Parliament and Council. (2016). General Data Protection Regulation (EU) 2016/679. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj

FAUZIAH, S., & SANTOSA, P. B. (2024). Pengaruh Fintech Lending (Paylater) Dan E-Money Terhadap Perilaku Impulsive Buying Pada Generasi Muslim Z di Kota Semarang (Thesis, UNDIP: Fakultas Ekonomika dan Bisnis).

Firdaus, N. A. (2023). Tinjauan Hukum Islam Dan Peraturan Otoritas Jasa Keuangan Nomor 77/PJOK. 01/2016 Terhadap Praktik Pinjaman Shopee Paylater (SPayLater) (Undergraduate (S1) Thesis, IAIN Ponorogo).

Marzuki, P. M. (2017). Legal research. Prenada Media Group.

Muhtada, D., & Diniyanto, A. (2021). Penataan Regulasi di Indonesia Melalui Lembaga Independen. Pandecta Research Law Journal, 16(2), 279-291. https://doi.org/10.15294/pandecta.v16i2.31866

Prasetyo, T. (2019). Legal research: A perspective of the theory of dignified justice. Nusa Media.

Rahmawati, S. (2021). Consumer data privacy in fintech lending. Jurnal Hukum & Regulasi Digital, 3(1), 1–4.

Sabiq, F. (2022). PayLater reviewed from Law Number 11 of 2008 concerning Electronic Information and Transactions and Fatwa DSN-MUI No: 117/DSN-MUI/II/2018. El-Hayah, 12(1), 1–12. https://ejournal.uinsaid.ac.id/index.php/el-hayah/article/view/5461

Satyanegara, N., Priyono, J., & Paulus, D. H. (2020). Personal data protection in Indonesia in the context of electronic commerce (e-commerce). Diponegoro Law Journal, 9(2), 1–10.

Solove, D. J. (2008). Understanding privacy. Harvard University Press.

Usman, R. (2017). Characteristics of Electronic Money in the Payment System. Finance Review, 32(1), 89-96.

Yustisia, A., & Perdana, F. (2022). Legal protection of consumers in fintech services. Jurnal IUS, 10(2), 1–10.

Downloads

Published

2025-05-31

Issue

Section

Articles

How to Cite

Noviyanti, D., Yuniwati, & Suratno. (2025). Legal Protection Analysis of Personal Data Breaches in Shopee Paylater Consumer Loan Transactions. Journal of Law and Economics, 4(1), 39-49. https://doi.org/10.56347/jle.v4i1.240
Most read articles by the same author(s)

Other papers published by author(s) in this journal:

Normative Approach to Law and Economics in Developing Countries: Challenges in Establishing Efficient and Just Market Regulations
Perizinan Berusaha dalam Perspektif Hukum Administrasi Negara dan Ekonomi