2016-12-30 | 77/POJK.01/2016Added
The Financial Services Authority (OJK) establishes regulations for Information Technology-Based Money Lending Services, requiring operators to be Indonesian legal entities with a minimum paid-up capital of IDR 2.5 billion at the licensing stage and a maximum lending limit of IDR 2 billion per borrower. The regulation mandates a two-stage registration and licensing process, imposes strict eligibility criteria for directors and commissioners, and defines the rights and obligations of lenders and borrowers, including the requirement for electronic contracts and periodic reporting to the OJK.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
BY THE GRACE OF GOD THE ALMIGHTY,
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that information technology has been used to develop the financial industry, which can drive the growth of alternative financing for the public; b. that in order to support the growth of information technology-based financial service institutions so that they can contribute more to the national economy;
c. that based on the considerations as referred to in letters a and b, it is necessary to establish a Financial Services Authority Regulation concerning Information Technology-Based Money Lending Services;
Recalling:
Law Number 21 of 2011 concerning the Financial Services Authority (State Gazette of the Republic of Indonesia of 2011 Number 111, Supplement to the State Gazette of the Republic of Indonesia Number 5253);
THE FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
COPY
RESOLVES:
Establish: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING INFORMATION TECHNOLOGY-BASED MONEY LENDING SERVICES.
GENERAL PROVISIONS
In this Financial Services Authority Regulation, the following terms are defined:
Financial Services Authority, hereinafter abbreviated as OJK, is an independent institution that has the functions, duties, and authorities for regulation, supervision, examination, and investigation as referred to in Law Number 21 of 2011 concerning the Financial Services Authority.
Other Financial Service Institutions are pawnshops, guarantee institutions, Indonesian export financing institutions, secondary housing financing companies, and institutions that manage public funds on a mandatory basis, including social security, pension, and welfare program organizers, as referred to in legislation regarding pawnshops, guarantees, Indonesian export financing institutions, secondary housing financing companies, and institutions that manage public funds on a mandatory basis, as well as other financial service institutions declared to be supervised by the OJK based on legislation.
Information Technology-Based Money Lending Services is the provision of financial services to match lenders with borrowers to conduct loan agreements in Rupiah directly through an electronic system using an internet network.
Electronic System is a series of electronic devices and procedures that function to prepare, collect, process, analyze, store, display, announce, send, and/or disseminate electronic information in the field of financial services.
Information Technology is a technique to collect, prepare, store, process, announce, analyze, and/or disseminate information in the field of financial services.
Information Technology-Based Money Lending Service Organizer, hereinafter referred to as the Organizer, is an Indonesian legal entity that provides, manages, and operates Information Technology-Based Money Lending Services.
Borrower is a person and/or legal entity that has debt due to an Information Technology-Based Money Lending Service agreement.
Lender is a person, legal entity, and/or business entity that has a claim due to an Information Technology-Based Money Lending Service agreement.
User of Information Technology-Based Money Lending Services, hereinafter referred to as the User, is the Lender and Borrower who use Information Technology-Based Money Lending Services.
Board of Directors:
a. for Organizers in the form of a limited liability company, is the Board of Directors as referred to in Law Number 40 of 2007 concerning Limited Liability Companies; or b. for Organizers in the form of a cooperative legal entity, is the Management as referred to in Law Number 25 of 1992 concerning Cooperatives.
Board of Commissioners:
a. for Organizers in the form of a limited liability company, is the Board of Commissioners as referred to in Law Number 40 of 2007 concerning Limited Liability Companies; or b. for Organizers in the form of a cooperative legal entity, is the Supervisors as referred to in Law Number 25 of 1992 concerning Cooperatives.
Electronic Document is any electronic information created, forwarded, sent, received, or stored in analog, digital, electromagnetic, optical, or similar forms, which can be seen, displayed, and/or heard through a computer or Electronic System, including but not limited to writing, sound, images, design maps, photos or similar, letters, signs, numbers, access codes, symbols, or perforations that have meaning or significance or can be understood by a person capable of understanding them, as referred to in Law Number 11 of 2008 concerning Information and Electronic Transactions.
Electronic Certificate is an electronic certificate containing an electronic signature and identity that shows the legal status of the parties in an electronic transaction issued by an electronic certification service provider as referred to in Law Number 11 of 2008 concerning Information and Electronic Transactions.
Electronic Certification Service Provider is a legal entity that functions as a party that provides and audits Electronic Certificates registered with the OJK.
Electronic Signature is a signature consisting of electronic information attached, associated, or related to other electronic information used as a verification and authentication tool as referred to in Law Number 11 of 2008 concerning Information and Electronic Transactions.
INFORMATION TECHNOLOGY-BASED MONEY LENDING SERVICE ORGANIZERS
Legal Entity Form, Ownership, and Capital
(1) The Organizer is declared as an Other Financial Service Institution.
(2) The Organizer's legal entity form is:
a. a limited liability company; or b. a cooperative.
(1) An Organizer in the form of a limited liability legal entity as referred to in Article 2 paragraph (2) letter a may be established and owned by:
a. Indonesian citizens and/or Indonesian legal entities; and/or b. foreign citizens and/or foreign legal entities.
(2) Share ownership of the Organizer by foreign citizens and/or foreign legal entities as referred to in paragraph (1) letter b, whether directly or indirectly, is at most 85% (eighty-five percent).
(1) An Organizer in the form of a limited liability legal entity must have paid-up capital of at least IDR 1,000,000,000.00 (one billion Rupiah) at the time of registration. (2) An Organizer in the form of a cooperative legal entity must have own capital of at least IDR 1,000,000,000.00 (one billion Rupiah) at the time of registration. (3) The Organizer must have paid-up capital as referred to in paragraph (1) or own capital as referred to in paragraph (2) of at least IDR 2,500,000,000.00 (two billion five hundred million Rupiah) at the time of submitting a licensing application.
Business Activities
(1) The Organizer provides, manages, and operates Information Technology-Based Money Lending Services from the Lender to the Borrower, where the source of funds comes from the Lender. (2) The Organizer may cooperate with other information technology-based financial service service providers in accordance with applicable legislation.
Limits on Lending Funds
(1) The Organizer must comply with the maximum total lending limit to each Borrower.
(2) The maximum total lending limit as referred to in paragraph (1) is set at IDR 2,000,000,000.00 (two billion Rupiah).
(3) The OJK may review the maximum total lending limit as referred to in paragraph (2).
Registration and Licensing
The Organizer must submit registration and licensing applications to the OJK.
Registration
(1) An Organizer intending to conduct Information Technology-Based Money Lending Services submits a registration application to the OJK.
(2) An Organizer that has conducted Information Technology-Based Money Lending Services before this OJK Regulation is promulgated must submit a registration application to the OJK no later than 6 (six) months after this OJK Regulation takes effect. (3) The registration application by the Organizer as referred to in paragraph (1) and paragraph (2) is submitted by the Board of Directors to the Executive Head of Supervision of Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions using Form 1 as contained in the Appendix which is an integral part of this OJK Regulation, and attached with documents containing at least:
a. the deed of establishment of the legal entity including the articles of association and any amendments thereto that have been approved/approved by the competent authority or notified to the competent authority in accordance with applicable legislation; b. proof of identity and a curriculum vitae completed with the latest 4x6 cm color passport photos from:
(1) An Organizer that has been registered must submit periodic reports every 3 (three) months for periods ending on March 31, June 30, September 30, and December 31 to the OJK with information containing at least:
a. the number of Lenders and Borrowers; b. the quality of loans received by Borrowers including the basis for loan quality assessment; and
c. activities conducted after registration with the OJK.
(2) The periodic report every 3 (three) months as referred to in paragraph (1) is submitted to the OJK no later than 10 (ten) working days calculated from the due date of the reporting date.
(1) An Organizer that has been registered with the OJK must submit a license application as an Organizer within a maximum period of 1 (one) year from the date of registration with the OJK. (2) In the event that the time period as referred to in paragraph (1) has expired, an Organizer that has obtained a certificate of registration and has not submitted a licensing application or does not meet licensing requirements, the certificate of registration as referred to in Article 8 paragraph (5) is declared void. (3) An Organizer whose certificate of registration is declared void as referred to in paragraph (2) can no longer submit a registration application to the OJK. (4) An Organizer whose certificate of registration is declared void as referred to in paragraph (2) must settle User rights and obligations in accordance with the statement letter regarding the settlement plan. (5) An Organizer that is still registered and declares itself unable to continue operational activities must submit an application to the OJK accompanied by reasons for inability and a plan for settling User rights and obligations.
Licensing
(1) The Organizer's licensing application as referred to in Article 10 paragraph (1) is submitted by the Organizer's Board of Directors to the Executive Head of Supervision of Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions using Form 2 as contained in the Appendix which is an integral part of this OJK Regulation and attached with at least:
a. the deed of establishment of the legal entity including the articles of association and any amendments thereto that have been approved/approved by the competent authority or notified to the competent authority, containing at least:
e. photocopy of proof of capital fulfillment legalized and still valid during the licensing application process in the name of one of the general banks conducting conventional business and/or based on Sharia principles with Indonesian legal entity status; f. the Organizer's organizational structure; g. guidelines/operational standard procedures related to the implementation of anti-money laundering and counter-terrorism financing programs; h. a work plan for the first 1 (one) year containing at least:
Ownership Changes
Changes in the Organizer's ownership must first obtain approval from the OJK.
Revocation of License Upon Own Request
(1) An Organizer that has obtained a license and declares itself unable to continue operational activities must submit an application to the OJK accompanied by reasons for inability and a plan for settling User rights and obligations. (2) The OJK revokes the Organizer's license no later than 20 (twenty) working days from the date of the application as referred to in paragraph (1).
Human Resource Qualifications
(1) The Organizer must have human resources with expertise and/or background in the field of information technology.
(2) The Organizer must have at least 1 (one) member of the Board of Directors and 1 (one) member of the Board of Commissioners with at least 1 (one) year of experience in the financial services industry. (3) The Organizer must improve the quality of human resources through education and training activities that support the development of Information Technology-Based Money Lending Services.
USERS OF INFORMATION TECHNOLOGY-BASED MONEY LENDING SERVICES
Borrowers
(1) Borrowers must originate from and reside within the legal jurisdiction of the Unitary State of the Republic of Indonesia.
(2) Borrowers as referred to in paragraph (1) consist of:
a. individual Indonesian citizens; or b. Indonesian legal entities.
Lenders
(1) Lenders may originate from within and/or outside the country.
(2) Lenders as referred to in paragraph (1) consist of:
a. individual Indonesian citizens; b. individual foreign citizens;
c. Indonesian/foreign legal entities;
d. Indonesian/foreign business entities; and/or e. international institutions.
(1) The Organizer provides input on the interest rates offered by Lenders and Borrowers considering fairness and the development of the national economy.
(2) In the event that Borrowers receive loans from abroad, the provision of Information Technology-Based Money Lending Services is subject to applicable legislation.
INFORMATION TECHNOLOGY-BASED MONEY LENDING SERVICE AGREEMENTS
The implementation agreement for Information Technology-Based Money Lending Services includes:
a. an agreement between the Organizer and the Lender; and b. an agreement between the Lender and the Borrower.
Agreement of Information Technology-Based Money Lending Service Organizer with Lender
(1) The agreement for the provision of Information Technology-Based Money Lending Services between the Organizer and the Lender is documented in an Electronic Document. (2) The Electronic Document as referred to in paragraph (1) must contain at least:
a. agreement number; b. agreement date;
c. identity of the parties;
d. provisions regarding the rights and obligations of the parties; e. loan amount; f. loan interest rate; g. commission amount; h. duration;
i. details of related costs;
j. provisions regarding penalties (if any); k. dispute resolution mechanism; and
l. resolution mechanism in the event that the Organizer cannot continue operational activities.
(3) The Organizer must provide information access to the Lender regarding the use of their funds.
(4) The information access as referred to in paragraph (3) does not include information related to the identity of the Borrower.
(5) Information on fund usage as referred to in paragraph (3) must contain at least:
a. the amount of funds lent to the Borrower; b. the purpose of fund utilization by the Borrower;
c. the loan interest rate amount; and
d. the loan duration.
Agreement of Lender with Borrower
(1) The loan agreement between the Lender and the Borrower is documented in an Electronic Document.
(2) The Electronic Document as referred to in paragraph (1) must contain at least:
a. agreement number; b. agreement date;
c. identity of the parties;
d. provisions regarding the rights and obligations of the parties; e. the loan amount; f. the loan interest rate; g. the installment value; h. the loan term;
i. collateral object (if any);
j. details of related costs; k. provisions regarding penalties (if any); and
l. dispute resolution mechanisms.
(3) Service Providers are required to provide information access to Borrowers regarding the received loan position.
(4) The information access referred to in paragraph (3) does not include information related to the identity of the Lender.
CHAPTER V
RISK MITIGATION
Article 21
Service Providers and Users must conduct risk mitigation.
Article 22
Service Providers may become members of the OJK financial information service system or other information service systems registered with the OJK, meeting requirements in accordance with applicable laws and regulations.
Article 23
Service Providers may cooperate and exchange data with information technology-based support service providers to improve the quality of Information Technology-Based Lending Services.
Article 24
(1) Service Providers are required to use escrow accounts and virtual accounts for Information Technology-Based Lending Services.
(2) Service Providers are required to provide virtual accounts for each Lender.
(3) For loan repayment, Borrowers make payments through the Service Provider's escrow account to be forwarded to the Lender's virtual account.
CHAPTER VI
INFORMATION TECHNOLOGY SYSTEM GOVERNANCE
PROVISION OF INFORMATION TECHNOLOGY-BASED LENDING SERVICES
First Section
Data Centers and Disaster Recovery Centers
Article 25
(1) Service Providers are required to use data centers and disaster recovery centers.
(2) Data centers and disaster recovery centers referred to in paragraph (1) must be located in Indonesia.
(3) Service Providers must meet minimum standards for information technology systems, information technology risk management, information technology security, resilience against system disturbances and failures, and information technology system outsourcing.
Second Section
Data Confidentiality
Article 26
Service Providers are required to:
a. maintain the confidentiality, integrity, and availability of personal data, transaction data, and financial data they manage from the time the data is obtained until the data is destroyed; b. ensure the availability of authentication, verification, and validation processes supporting non-repudiation in accessing, processing, and executing personal data, transaction data, and financial data they manage;
c. guarantee that the acquisition, use, utilization, and disclosure of personal data, transaction data, and financial data obtained by Service Providers are based on the consent of the owners of the personal data, transaction data, and financial data, unless otherwise determined by applicable laws and regulations;
d. provide other communication media besides the Information Technology-Based Lending Electronic System to ensure the continuity of customer services, which may include email, call centers, or other communication media; and e. notify in writing the owners of the personal data, transaction data, and financial data if there is a failure in protecting the confidentiality of the personal data, transaction data, and financial data they manage.
Third Section
Audit Trails
Article 27
(1) Service Providers are required to provide audit trails for all their activities within the Information Technology-Based Lending Electronic System.
(2) Service Providers must ensure that the information technology system equipment used supports the provision of audit trails.
(3) Audit trails referred to in paragraph (1) are used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations.
Fourth Section
Security Systems
Article 28
(1) Service Providers are required to secure information technology system components by having and implementing procedures and facilities for securing Information Technology-Based Lending Services to avoid disturbances, failures, and losses. (2) Service Providers are required to provide security systems covering procedures, prevention systems, and handling of threats and attacks that cause disturbances, failures, and losses. (3) Service Providers must participate in the management of information technology vulnerabilities to support information security within the information technology-based financial services industry. (4) Service Providers are required to display Electronic Documents in full according to the format and retention period established in accordance with applicable laws and regulations.
CHAPTER VII
EDUCATION AND PROTECTION OF USERS OF INFORMATION TECHNOLOGY-BASED LENDING SERVICES
Article 29
Service Providers are required to apply basic principles of User protection, namely:
a. transparency; b. fair treatment;
c. reliability;
d. data confidentiality and security; and e. simple, fast, and affordable User dispute resolution.
Article 30
(1) Service Providers are required to provide and/or convey current information regarding Information Technology-Based Lending Services that is accurate, honest, clear, and not misleading. (2) Information referred to in paragraph (1) is formulated in documents or other means that can be used as evidence.
Article 31
(1) Service Providers are required to convey information to Users regarding the acceptance, postponement, or rejection of Information Technology-Based Lending Service applications. (2) In the event that Service Providers convey information regarding the postponement or rejection of financial services applications as referred to in paragraph (1), Service Providers are required to convey the reasons for the postponement or rejection unless otherwise regulated by applicable laws and regulations.
Article 32
(1) Service Providers are required to use simple terms, phrases, and/or sentences in the Indonesian language that are easy to read and understand by Users in every Electronic Document. (2) The Indonesian language in documents as referred to in paragraph (1) may be paired with other languages if necessary.
Article 33
Service Providers support the implementation of activities to increase financial literacy and inclusion.
Article 34
Service Providers are required to consider the suitability between User needs and capabilities with the services offered to Users.
Article 35
Service Providers are required to include and/or mention in every offer or promotion of services consisting of:
a. the name and/or logo of the Service Provider; and b. a statement that the Service Provider is registered and supervised by the OJK.
Article 36
(1) In the event that Service Providers use standard agreements, such standard agreements must be drafted in accordance with applicable laws and regulations. (2) Standard agreements as referred to in paragraph (1) used by Service Providers are prohibited from:
a. stating the transfer of responsibilities or obligations of the Service Provider to Users; and b. stating that Users are subject to new, additional, continuing, and/or changes made unilaterally by the Service Provider during the period Users utilize the services.
Article 37
Service Providers are responsible for losses suffered by Users resulting from errors and/or negligence by the Board of Directors, and/or employees of the Service Provider.
Article 38
Service Providers must have operational standard procedures for serving Users, contained in Electronic Documents.
Article 39
(1) Service Providers are prohibited from providing data and/or information regarding Users to third parties in any manner.
(2) The prohibition as referred to in paragraph (1) is excepted in the event:
a. Users provide electronic consent; and/or b. required by applicable laws and regulations.
(3) Cancellation or partial change of consent regarding the disclosure of data and/or information as referred to in paragraph (2) letter a is conducted electronically by Users in the form of Electronic Documents.
Article 40
Service Providers are required to report electronically every month in the event of User complaints, accompanied by follow-up on the resolution of such complaints, to the OJK.
CHAPTER VIII
ELECTRONIC SIGNATURES
Article 41
(1) Agreements as referred to in Article 18 are implemented using electronic signatures.
(2) Agreements other than those referred to in paragraph (1) that are drafted for the provision of Information Technology-Based Lending Services may use electronic signatures. (3) The use of electronic signatures as referred to in paragraph (1) and paragraph (2) must be implemented in accordance with applicable laws and regulations governing electronic signatures.
CHAPTER IX
PRINCIPLES AND TECHNIQUES OF CUSTOMER IDENTIFICATION
Article 42
Service Providers are required to implement anti-money laundering and counter-terrorism financing programs in the financial services sector for Users in accordance with applicable laws and regulations regarding the implementation of anti-money laundering and counter-terrorism financing programs.
CHAPTER X
PROHIBITIONS
Article 43
In conducting business activities, Service Providers are prohibited from:
a. conducting business activities other than those of Service Providers regulated in this OJK Regulation; b. acting as Lenders or Borrowers;
c. providing guarantees in any form for the fulfillment of other parties' obligations;
d. issuing debt instruments; e. providing recommendations to Users; f. publishing fictitious and/or misleading information; g. offering services to Users and/or the public through personal communication means without User consent; and h. charging any fees to Users for submitting complaints.
CHAPTER XI
PERIODIC REPORTS
Article 44
Service Providers that have obtained licenses are required to submit periodic reports electronically to the OJK, namely:
a. monthly reports; and b. annual reports.
Article 45
(1) Monthly reports of Service Providers must at least contain:
a. financial performance reports of Information Technology-Based Lending Service Providers submitted in the form of physical documents and Electronic Documents; b. service performance reports of Information Technology-Based Lending Services in the form of physical documents and Electronic Documents;
c. Electronic Documents in database format with the structure of database elements of Information Technology-Based Lending Services; and
d. User complaints accompanied by follow-up on complaint resolution as referred to in Article 40; according to Form 3 as stated in the Appendix which is an integral part of this OJK Regulation. (2) In the event necessary, the OJK may request additional information and/or data from Service Providers. (3) Monthly reports are submitted in the form of physical documents and electronic documents. (4) Monthly reports as referred to in paragraph (3) are submitted to the Executive Head of Supervision of Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions no later than 10 (ten) working days in the following month. (5) Submission of monthly report information as referred to in paragraph (1) letter d is copied to members of the Commission Council for Education and Consumer Protection.
Article 46
(1) Service Providers are required to submit annual reports to the OJK for the reporting period from January 1 to December 31.
(2) Annual reports consist of:
a. financial reports; and b. reports on the implementation of Information Technology-Based Lending Services; according to Form 4 as stated in the Appendix which is an integral part of this OJK Regulation. (3) In the event necessary, the OJK may request additional information and/or data from Service Providers. (4) Annual reports are submitted in the form of physical documents and electronic documents. (5) Annual reports as referred to in paragraph (4) are submitted to the Executive Head of Supervision of Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions no later than 20 (twenty) working days after the reporting period ends.
CHAPTER XII
SANCTIONS
Article 47
(1) For violations of obligations and prohibitions in this OJK Regulation, the OJK has the authority to impose administrative sanctions on Service Providers, namely:
a. written warnings; b. fines, namely the obligation to pay a certain amount of money;
c. restrictions on business activities; and
d. license revocation.
(2) Administrative sanctions as referred to in paragraph (1) letters b to d may be imposed with or without prior imposition of administrative sanctions in the form of written warnings as referred to in paragraph (1) letter a. (3) Administrative sanctions in the form of fines as referred to in paragraph (1) letter b may be imposed separately or together with the imposition of administrative sanctions as referred to in paragraph (1) letters c and d.
CHAPTER XIII
OTHER PROVISIONS
Article 48
Service Providers are required to be members of associations designated by the OJK.
CHAPTER XIV
TRANSITIONAL PROVISIONS
Article 49
The implementation of cooperation between Service Providers and information technology-based support service providers registered with the OJK as referred to in Article 23 takes effect 2 (two) years after this OJK Regulation is enacted.
Article 50
At the time this OJK Regulation takes effect, Information Technology-Based Lending Service agreements that are still ongoing with loan amounts exceeding the maximum total loan provision limit as referred to in Article 6, may continue until the end of the term of such agreements.
CHAPTER XV
CLOSING PROVISIONS
Article 51
Further provisions regarding Information Technology-Based Lending Services, including changes to the maximum total loan provision limit, loan provision procedures, cooperation between Service Providers and other information technology-based support service providers, placement of data centers and minimum standards for information technology systems, information technology risk management, information technology security, resilience against system disturbances and failures, and information technology system outsourcing, security systems, data confidentiality, system transaction failures of Service Providers, information technology system security, management of information technology vulnerabilities, retention of information and/or Electronic Documents, and procedures for the use of Electronic Signatures in the provision of Information Technology-Based Lending Services, are regulated in OJK circular letters.
Article 52
This OJK Regulation takes effect upon enactment.
To ensure that everyone knows it, ordering the enactment of this OJK Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on December 28, 2016
CHAIRMAN OF THE COMMISSION COUNCIL
FINANCIAL SERVICES AUTHORITY, signed
MULIAMAN D. HADAD
Enacted in Jakarta on December 29, 2016
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2016 NUMBER 324 Copy in accordance with the original Legal Director 1 Legal Department signed Yuliana
Read the rest free
Amended 1 time · last 2022-07-04
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works