2020-06-18 | 38/POJK.05/2020Added · Updated
The Financial Services Authority (OJK) amends Regulation 69/POJK.05/2016 to permit insurance and reinsurance companies to locate data centers and disaster recovery centers outside Indonesia for specific integrated purposes, including global regulatory analysis, group risk management, anti-money laundering compliance, and internal group management. This exemption requires prior OJK approval and mandates that companies submit country risk analyses, ensure OJK supervisory effectiveness, maintain Indonesian law in contracts, and provide access rights to OJK. The amendment also updates Article 77 to clarify administrative sanctions for violations, including specific penalties for Sharia Units, and deletes Article 83. These changes apply to insurance companies, Sharia insurance companies, reinsurance companies, and Sharia reinsurance companies.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
COPY
FINANCIAL SERVICES AUTHORITY REGULATION REPUBLIC OF INDONESIA NUMBER 38 /POJK.05/2020 CONCERNING AMENDMENT TO FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 69/POJK.05/2016 CONCERNING THE CONDUCT OF BUSINESS BY INSURANCE COMPANIES, SHARIA INSURANCE COMPANIES, REINSURANCE COMPANIES, AND SHARIA REINSURANCE COMPANIES BY THE GRACE OF THE MOST HIGH GOD THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY, Considering:
a. that to carry out business activities, it is necessary to be supported by data management that can generate accurate and accountable information for decision-making; Insurance Companies are required to place data in data centers and disaster recovery centers within the Indonesian territory; b. that the placement of data in an integrated manner with the parent company of insurance companies, Sharia insurance companies, reinsurance companies, and Sharia reinsurance companies outside the Indonesian territory supports the utilization of data in electronic systems at data centers and disaster recovery centers abroad;
c. that the placement of data in electronic systems at data centers and disaster recovery centers outside the Indonesian territory is not yet regulated in Financial Services Authority Regulation Number 69/POJK.05/2016 concerning the Conduct of Business by Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies, so adjustments are needed;
d. that based on the considerations as referred to in letters a, b, and c, it is necessary to establish a Financial Services Authority Regulation concerning the Amendment to Financial Services Authority Regulation Number 69/POJK.05/2016 concerning the Conduct of Business by Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies; Recalling:
NUMBER 69/POJK.05/2016 CONCERNING THE CONDUCT OF BUSINESS BY INSURANCE COMPANIES, SHARIA INSURANCE COMPANIES, REINSURANCE COMPANIES, AND SHARIA REINSURANCE COMPANIES.
Article I
Several provisions in the Financial Services Authority Regulation Number 69/POJK.05/2016 concerning the Conduct of Business by Insurance Companies, Sharia Insurance Companies, Reinsurance Companies, and Sharia Reinsurance Companies (State Gazette of the Republic of Indonesia Year 2016 Number 302, Supplement to the State Gazette of the Republic of Indonesia Number
5992) are amended as follows:
d. submits a letter of statement of no objection from the supervisory authority of the information technology service provider of the data center and disaster recovery center outside the Indonesian territory and the information technology service provider that OJK is granted access to conduct examinations of the information technology service provider of the data center and disaster recovery center; e. submits a letter of statement that the Company will periodically submit the results of assessments conducted by the parent company, ultimate parent entity, and/or other entities that have similar business activities within one Company group outside the Indonesian territory regarding the application of risk management on the information technology service provider of the data center and disaster recovery center; f. ensures that the benefits of the planned placement of data in data centers and disaster recovery centers outside the Indonesian territory for the Company are greater than the burdens borne by the Company; and g. submits the Company's plan to improve the Company's human resource capabilities both related to the conduct of information technology as well as business transactions or products offered. (4) The Company is required to ensure that data placed in data centers and disaster recovery centers outside the Indonesian territory is not used for purposes other than those referred to in paragraph (1). (5) OJK has the authority to request Companies that have obtained approval as referred to in paragraph (2) to place data in data centers and disaster recovery centers within the Indonesian territory if, based on evaluations conducted by OJK, it is known:
a. does not comply with the data placement plan in data centers and disaster recovery centers outside the Indonesian territory submitted to OJK; b. has the potential to reduce the effectiveness of OJK supervision;
c. has the potential to negatively impact the Company's performance; and/or
d. does not comply with statutory regulations.
(6) The Company is required to fulfill OJK's request to place data in data centers and disaster recovery centers within the Indonesian territory as referred to in paragraph (5).
2. Paragraphs (1), (2), and (5) of Article 77 are amended
and 1 (one) paragraph is added, namely paragraph (6), so that
Article 77 reads as follows:
Article 77
(1) Violations of the provisions in Article 2,
Article 3, Article 4, Article 5, Article 7 paragraph (2) and paragraph
(3), Article 8 paragraph (1), paragraph (2), and paragraph (3), Article 9,
Article 12, Article 13, Article 14, Article 15 paragraph (1),
paragraph (2), paragraph (4), and paragraph (5), Article 16 paragraph (1) and paragraph (2), Article 17, Article 18, Article 19, Article 20, Article 22 paragraph (2) and paragraph (3), Article 24, Article 25 paragraph (1), Article 26, Article 27 paragraph (2), Article 28,
Article 29 paragraph (5), paragraph (6), paragraph (7) and paragraph (9),
Article 30, Article 31, Article 32, Article 33, Article 34,
Article 35, Article 36, Article 37 paragraph (1) and paragraph (3),
Article 38 paragraph (1) and paragraph (3), Article 39 paragraph (1),
paragraph (2), and paragraph (3), Article 40, Article 41, Article 44 paragraph (3), Article 45 paragraph (1), paragraph (2), and paragraph (3),
Article 46 paragraph (1) and paragraph (2), Article 47, Article 48
paragraph (1) and paragraph (2), Article 49, Article 49A paragraph (2), paragraph (4) and paragraph (6), Article 50, Article 51 paragraph (2),
Article 53, Article 54 paragraph (1), paragraph (2), paragraph (4), paragraph
(5), paragraph (6), and paragraph (8), Article 55 paragraph (2), Article 56 paragraph (2) and paragraph (4), Article 57 paragraph (2), Article 58 paragraph (2), Article 59 paragraph (2), Article 60 paragraph (1), paragraph (6), and paragraph (7), Article 61, Article 63, Article 65 paragraph (2), Article 66 paragraph (1), paragraph (4), and paragraph (5),
Article 67 paragraph (3), paragraph (5), paragraph (6), and paragraph (7),
Article 68, Article 69, Article 71 paragraph (1), paragraph (2), paragraph
(3), paragraph (5), paragraph (6), and paragraph (7), Article 72 paragraph (1), paragraph (3), and paragraph (4), Article 73, Article 75 paragraph (1), and Article 76 paragraph (1) are subject to administrative sanctions in the form of:
a. written warning; b. restriction of business activities, for part or all of the business activities; and
c. revocation of business license.
(2) In the event of violations of the provisions in
Article 3, Article 5, Article 7 paragraph (2) and paragraph (3),
Article 8 paragraph (1) paragraph (2) and paragraph (3), Article 9,
Article 12 paragraph (3), Article 14, Article 15 paragraph (1), paragraph
(2), paragraph (4), and paragraph (5), Article 16 paragraph (1) and paragraph (2), Article 17, Article 18, Article 19, Article 20,
Article 22 paragraph (2) and paragraph (3), Article 24, Article 25
paragraph (1), Article 26, Article 27 paragraph (2), Article 28,
Article 29 paragraph (5), paragraph (6), paragraph (7), and paragraph (9),
Article 30, Article 31, Article 32, Article 33, Article 34,
Article 35, Article 36, Article 37 paragraph (1) and paragraph (3),
Article 38 paragraph (1) and paragraph (3), Article 39 paragraph (1),
paragraph (2), and paragraph (3), Article 40, Article 41, Article 44 paragraph (3), Article 45 paragraph (1), paragraph (2), and paragraph (3),
Article 47, Article 48 paragraph (1) and paragraph (2), Article 49,
Article 49A paragraph (2), paragraph (4), and paragraph (6), Article 50,
Article 51 paragraph (2), Article 53, Article 54 paragraph (1), paragraph
(2), paragraph (4), paragraph (5), paragraph (6), and paragraph (8), Article 55 paragraph (2), Article 56 paragraph (2) and paragraph (4), Article 57 paragraph (2) and paragraph (4), Article 58 paragraph (2), Article 59 paragraph (2), Article 60 paragraph (1), paragraph (6), and paragraph (7), Article 61, Article 63, Article 65 paragraph (2), Article 66 paragraph (1), paragraph (4), and paragraph (5), Article 67 paragraph (3), paragraph (5), paragraph (6), and paragraph (7), Article 68, Article 69,
Article 71 paragraph (1), paragraph (2), paragraph (3), paragraph (5), paragraph
(6), and paragraph (7), Article 72 paragraph (1), paragraph (3), and paragraph (4), Article 73, Article 75 paragraph (1), and Article 76 paragraph (1) committed by the Sharia Unit are subject to administrative sanctions in the form of:
a. written warning; b. restriction of business activities of the Sharia Unit, for part or all of the business activities; and
c. revocation of the license to establish the Sharia Unit.
(3) Administrative sanctions as referred to in paragraph (1) or paragraph (2) are carried out progressively. (4) In addition to administrative sanctions as referred to in paragraph (1) and paragraph (2), OJK may add additional sanctions in the form of:
a. prohibition on marketing insurance products or Sharia insurance products for certain business lines; and/or
b. prohibition on becoming a shareholder, controller, director, board of commissioners, or equivalent to shareholder, controller, director, and board of commissioners, or holding an executive position below the board of directors, or equivalent to the executive position below the board of directors, in an insurance company. (5) OJK may impose a business license revocation sanction without prior imposition of other administrative sanctions for violations of Article 8 paragraph (3). (6) Procedures and methods for imposing administrative sanctions are carried out in accordance with the Financial Services Authority Regulation regarding procedures and methods for imposing administrative sanctions in the insurance sector and blocking the assets of insurance companies, Sharia insurance companies, reinsurance companies, and Sharia reinsurance companies.
3. Article 83 is deleted.
Article II
This Financial Services Authority Regulation comes into force on the date of its enactment.
This copy is in accordance with the original Deputy Director of Legal Consultation and Harmonization of Banking Regulations 1 Legal Directorate 1 Legal Department signed Wiwit Puspasari To ensure that everyone knows it, order the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia. Established in Jakarta on June 15, 2020 CHAIRMAN OF THE BOARD OF COMMISSIONERS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed WIMBOH SANTOSO Enacted in Jakarta on June 18, 2020 MINISTER OF LAW AND HUMAN RIGHTS REPUBLIC OF INDONESIA, signed YASONNA H. LAOLY STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2020 NUMBER 149
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION REPUBLIC OF INDONESIA NUMBER 38 /POJK.05/2020 CONCERNING AMENDMENT TO FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 69/POJK.05/2016 CONCERNING THE CONDUCT OF BUSINESS BY INSURANCE COMPANIES, SHARIA INSURANCE COMPANIES, REINSURANCE COMPANIES, AND SHARIA REINSURANCE COMPANIES
I. GENERAL
In the context of data management that can generate accurate and accountable information for decision-making, Companies are required to place data in data centers and disaster recovery centers within the Indonesian territory. The placement of data in an integrated manner with the parent company of insurance companies, Sharia insurance companies, reinsurance companies, and Sharia reinsurance companies outside the Indonesian territory supports the utilization of data in electronic systems at data centers and disaster recovery centers abroad. To support the effectiveness of such data placement, it is necessary to refine the provisions. In addition to supporting the intended utilization, it is also necessary to strengthen supervision in the use of data in electronic systems at data centers and disaster recovery centers abroad. In relation to this matter, it is necessary to refine the provisions regarding the conduct of business by insurance companies, Sharia insurance companies, reinsurance companies, and Sharia reinsurance companies.
II. ARTICLE BY ARTICLE
Article I
Number 1
Article 49A
Paragraph (1)
Letter a
It is clear enough.
Letter b
It is clear enough.
Letter c
It is clear enough.
Letter d
It is clear enough.
Letter e
Data used for internal management within one Company group does not relate to Company operations and/or services to policyholders, insured parties, and/or participants, including but not limited to employee data, remuneration data, and/or internal audit data. Paragraph (2) It is clear enough. Paragraph (3) Letter a The term "country risk analysis" refers to an analysis related to risk exposure from the country where data exchange with the Company takes place.
Letter b
The term "does not reduce the effectiveness of OJK supervision" means not causing difficulties for OJK in obtaining the necessary data and information, such as having access to databases and having a database structure for each application used. Letter c It is clear enough. Letter d The letter of statement is only submitted for the information technology service provider of the data center and disaster recovery center that has a supervisory authority. Letter e It is clear enough. Letter f Expected benefits include improved service quality for policyholders, insured parties, and/or participants, as well as the application of anti-money laundering and terrorism financing prevention programs. Letter g It is clear enough. Paragraph (4) It is clear enough. Paragraph (5) It is clear enough. Paragraph (6) It is clear enough. Number 2
Article 77
It is clear enough.
Number 3
Article 83
Deleted.
Article II
It is clear enough.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 6527
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.