Cybersecurity Guidelines for Financial Sector Te…

Indonesian Financial Services Authority

c. Customer Transaction Data Retention Period:

Transaction Records: Retain for 5 years from the date of the transaction.

Credit Card Information: Retain only as long as necessary for the transaction processing and dispute resolution, typically no more than 90 days.

Conditions: - Comply with Payment Card Industry Data Security Standard (PCI DSS) for handling and storage of credit card information. - Implement secure deletion processes for personal identity information after the retention period.

d. Business Communications Retention Period:

Emails: Retain for 3 years.

Instant Messaging & Chat Log: Retain for 1 year.

Conditions: - Ensure compliance with applicable regulations related to the retention of business communications. - Ensure secure retention of business communication data to protect against unauthorised access and ensure data integrity.

33

Made with FlippingBook. PDF to flipbook with ease