Cybersecurity Guidelines for Financial Sector Te…

Indonesian Financial Services Authority

3.2.3. Availability

1.

Data Retention Mechanisms

In terms of data retention, FSTI Providers are required to adhere to the following:

a) Data Retention Policy

- Establish a retention period policy according to the data category and type, such as transaction records, customer identification documents, and communication logs, each adhering to specific legal requirements. - Regularly update the retention policy according to the new regulatory changes applicable in Indonesia. - Data storage, data retention, and data destruction may refer to Law Number 43 of 2009 on Archives and/or Law No. 27 of 2022 on Personal Data Protection. - Below are specific guidelines for different types of data referring to the European Union GDPR 6 :

6 GDPR - General Data Protection Regulation: Regulations concerning data protection and privacy in the European Union and the European Economic Area.

31

Made with FlippingBook. PDF to flipbook with ease