Abstract
Artikel ini menganalisis konstruksi pengaturan Automatic Exchange of Information (AEOI) di Indonesia dalam perspektif kedaulatan siber serta kesesuaiannya dengan prinsip perlindungan data pribadi dan norma penyelenggaraan sistem elektronik. Ruang lingkup AEOI dalam artikel ini mencakup AEOI-CRS atas informasi rekening keuangan, Amended CRS, dan AEOI-CARF atas informasi aset kripto relevan sebagaimana dikonstruksikan dalam regulasi teknis terbaru. Penelitian menggunakan metode yuridis normatif dengan pendekatan perundang-undangan, konseptual, dan perbandingan terbatas terhadap standar OECD. Bahan hukum primer meliputi UU Nomor 9 Tahun 2017, UU KUP, UU PDP, UU ITE sebagaimana diubah terakhir dengan UU Nomor 1 Tahun 2024, PP Nomor 71 Tahun 2019, Perpres Nomor 82 Tahun 2022, PMK Nomor 108 Tahun 2025, PER-10/PJ/2025, CRS, Amended CRS, CARF MCAA, dan dokumen OECD mengenai confidentiality serta data safeguards. Hasil penelitian menunjukkan bahwa Indonesia memiliki legitimasi hukum yang memadai untuk melaksanakan AEOI. Namun, perluasan cakupan ke aset kripto memperbesar konsekuensi hukum terhadap transfer data lintas batas, pembatasan tujuan, kontrol akses, audit trail, keamanan sistem elektronik, dan akuntabilitas. Artikel ini menyimpulkan bahwa AEOI di Indonesia telah sesuai secara formal dengan prinsip pelindungan data pribadi, tetapi masih memerlukan penguatan substantif melalui harmonisasi norma, standar keamanan informasi yang spesifik, pembatasan pemanfaatan ulang data, dan pembagian tanggung jawab lintas aktor.
References
Abdullah, Abdulqadous, Suzan Mohammed Jawad Alkazraji, Ayah Ahmed Jasim, Aseel Ibraheem Muhsin, Faris Abdul Kareem Khazal, and Radomyr Mykolenko. “Sovereignty in the Digital Age: Social, Legal, and Governance Challenges of Global Networks.” Edited by Molamohamadi Z., Mirzazadeh A., Babaee Tirkolaee E., and Weber G.-W. Communications in Computer and Information Science 2855 CCIS (2026): 143 – 159. https://doi.org/10.1007/978-3-032-17023-1_8.
Alguliyev, Rasim, Yadigar Imamverdiyev, and Elchin Aliyev. “Conceptual Architecture of National Information Space Security System of Azerbaijan.” In 2012 4th International Conference “Problems of Cybernetics and Informatics”, PCI 2012 - Proceedings, 2012. https://doi.org/10.1109/ICPCI.2012.6486262.
Alzaqibh, Ahmad Aqeil, and Husein Bani Issa. “Digital Sovereignty and Data Localization in International Legal Systems: Trying to Balance State Control and the Global Digital Economy.” In 2026 ASU International Conference in Emerging Technologies for Sustainability and Intelligent Systems, ICETSIS 2026, 778 – 783. Institute of Electrical and Electronics Engineers Inc., 2026. https://doi.org/10.1109/ICETSIS68266.2026.11549231.
Aulia, E. (2024). Analisis Pasal 56 dalam Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi dari perspektif kepastian hukum. UNES Law Review, 7(1), 220-227. https://doi.org/10.31933/unesrev.v7i1.2267
Anggia, Putri, Aisyah Ajeng Putri Riyanto, Ani Yunita, and Wuku Astuti. “Legal Implications of FATCA in Indonesia: An Analysis of the Viability of the IGA Model 1C Approach.” Jambura Law Review 8, no. 1 (2026): 307 – 325. https://www.scopus.com/inward/record.uri?eid=2-s2.0-105042618524&partnerID=40&md5=484513d777ed18aa4ad14e8b0d206116.
Anggia, Putri, Ani Yunita, and Fadia Fitriyanti. “Legal Justice: The Abolition of the Principle of Bank Secrecy for Tax Interests in Indonesia.” Jambura Law Review 5, no. 2 (2023): 314 – 331. https://doi.org/10.33756/jlr.v5i2.18793.
Aydin, Atilla, and Turksel Kaya Bensghir. “Digital Data Sovereignty: Towards a Conceptual Framework.” In 1st International Informatics and Software Engineering Conference: Innovative Technologies for Digital Transformation, IISEC 2019 - Proceedings, edited by Varol A., Yazici A., Yazici M.A., Varol C., Aygunes G.S., and Cotur A. Institute of Electrical and Electronics Engineers Inc., 2019. https://doi.org/10.1109/UBMYK48245.2019.8965469.
Barrinha, André, and G Christou. “Speaking Sovereignty: The EU in the Cyber Domain.” European Security 31, no. 3 (2022): 356 – 376. https://doi.org/10.1080/09662839.2022.2102895.
Bhakti, Agus, Arfin Sudirman, R Widya Setiabudi Sumadinata, and Arry Bainus. “State Defense Strategy in Facing Cyber Threats After Hacking Incidents on Government Institutions: A Case Study in Indonesia.” Journal of Human Security 20, no. 1 (2024): 109 – 117. https://doi.org/10.12924/johs2024.20116.
Crasnic, Loriana, and Lukas Hakelberg. Power and Resistance in the Global Fight against Tax Evasion. Handbook on the Politics of Taxation. Edward Elgar Publishing Ltd., 2021. https://www.scopus.com/inward/record.uri?eid=2-s2.0-85126953254&partnerID=40&md5=a5822f9655d5fe6062695928e4616e29.
Darmanti, R. M., & Mangkan, D. (2020). The implementation of Automatic Exchange of Information as a tool to tackle offshore tax evasion: An experience from Indonesia. Scientax: Jurnal Kajian Ilmiah Perpajakan Indonesia, 2(1), 100-122. https://doi.org/10.52869/st.v2i1.61
Diamantopoulou, Vasiliki, Aggeliki Tsohou, and Maria Karyda. “From ISO/IEC 27002:2013 Information Security Controls to Personal Data Protection Controls: Guidelines for GDPR Compliance.” Edited by Katsikas S., Katsikas S., Cuppens F., Cuppens N., Lambrinoudakis C., Gritzalis S., Kalloniatis C., et al. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 11980 LNCS (2020): 238 – 257. https://doi.org/10.1007/978-3-030-42048-2_16.
Dilisen, Melike Melis. “Sovereignty over Cyber Territories.” International Journal of Interdisciplinary Civic and Political Studies 13, no. 3–4 (2018): 1 – 11. https://doi.org/10.18848/2327-0071/CGP/v13i02/1-11.
Eslam, Hisham, and Garima Tiwari. “Cyberspace: Reimagining Cybersecurity and Its Impact on State Sovereignty.” Studies in Computational Intelligence 1181 (2025): 93 – 112. https://doi.org/10.1007/978-3-031-80557-8_4.
Febriansyah, Ferry Irawan, Afiful Ikhwan, Ulya Shafa Firdausi, and Ayub Dwi Anggoro. “Digital Legal Transformation: Legal Strategies for Strengthening National Cybersecurity.” International Journal of Law and Society 5, no. 1 (2026): 26 – 44. https://doi.org/10.59683/ijls.v5i1.357.
Gadžo, Stjepan, and Irena Klemenčić. “Effective International Information Exchange as a Key Element of Modern Tax Systems: Promises and Pitfalls of the OECD’s Common Reporting Standard.” Public Sector Economics 41, no. 2 (2017): 207 – 226. https://doi.org/10.3326/pse.41.2.3.
Hummel, P., Braun, M., Tretter, M., & Dabrock, P. (2021). Data sovereignty: A review. Big Data & Society, 8(1), 1-17. https://doi.org/10.1177/2053951720982012
Halim, I. R. (2021). Analisis penegakan hukum Undang-Undang Nomor 9 Tahun 2017 tentang akses informasi keuangan untuk kepentingan perpajakan terkait data dan informasi perpajakan. Skripsi, Universitas Gadjah Mada.
Huang, Xiaoqing. “Ensuring Taxpayer Rights in the Era of Automatic Exchange of Information: EU Data Protection Rules and Cases.” Intertax 46, no. 3 (2018): 225 – 239. https://doi.org/10.54648/taxi2018024.
Hulitt, Elaine, and Rayford B Vaughn Jr. “Information System Security Compliance to FISMA Standard: A Quantitative Measure.” In Proceedings of the International Multiconference on Computer Science and Information Technology, IMCSIT 2008, 3:799 – 806, 2008. https://doi.org/10.1109/IMCSIT.2008.4747334.
Indirwan, and Sarah Safira Aulianisa. “Critical Review of The Urgency of Strenghthening The Implementation of Cyber Security and Resilience in Indonesia.” Lex Scientia Law Review 4, no. 1 (2020): 30 – 45. https://doi.org/10.15294/lesrev.v4i1.38197.
Ismail, Mahmoud, Noor Saleh Ali Alzyoud, Fayez A L Nusair, and Randa E L Hasi. “Conceptual and Legal Issues for National Cyber Sovereignty.” Edited by Alzoubi H.M., Al-Gasaymeh A.S., and Vasudevan S. Advances in Science, Technology and Innovation, 2025, 197 – 201. https://doi.org/10.1007/978-3-031-90558-2_25.
Karlova, Tatyana V, Alexander Y Bekmeshov, and Natalia M Kuznetsova. “Protection the Data Banks in State Critical Information Infrastructure Organizations.” In Proceedings of the 2019 IEEE International Conference Quality Management, Transport and Information Security, Information Technologies IT and QM and IS 2019, edited by Shaposhnikov S.O. and Saint Petersburg Saint Petersburg Electrotechnical University “LETI” Popov Str. 5, 155 – 157. Institute of Electrical and Electronics Engineers Inc., 2019. https://doi.org/10.1109/ITQMIS.2019.8928412.
Kawanishi, Yasuyuki, Hideaki Nishihara, Daisuke Souma, and Hirotaka Yoshida. “Detailed Analysis of Security Evaluation of Automotive Systems Based on JASO TP15002.” Edited by Bitsch F., Tonetta S., and Schoitsch E. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 10489 LNCS (2017): 211 – 224. https://doi.org/10.1007/978-3-319-66284-8_18.
Kurnia, Rizky Amalia, Dhata Praditya, and Marijn Janssen. “A Comparative Study of Business-to-Government Information Sharing Arrangements for Tax Reporting.” Edited by Dwivedi Y., Ayaburi E., Boateng R., and Effah J. IFIP Advances in Information and Communication Technology 558 (2019): 154 – 169. https://doi.org/10.1007/978-3-030-20671-0_11.
Mariyam, Siti, Adhi Putra Satria, Hariyanto, and Ahmad Masum. “Safeguarding Personal Data in Indonesian E-Commerce from A Constitutional Rights Perspective.” Jambe Law Journal 8, no. 2 (2025): 683 – 711. https://doi.org/10.22437/jlj.8.2.683-711.
Masiwal, Rishita, Nikita, Deepali Kamthania, and Shailee Bhatia. Balancing Technology and Trust: The Impact of Health Information Technology on Data Security and Patient Confidence in Healthcare. Quantum Learning: Bridging Artificial Intelligence, Quantum Computing, and Data Science in Education. CRC Press, 2026. https://doi.org/10.1201/9781003637400-16.
Mulyani, Sri, Suparno Suparno, and Retno Mawarini Sukmariningsih. “Regulations and Compliance in Electronic Commerce Taxation Policies: Addressing Cybersecurity Challenges in the Digital Economy.” International Journal of Cyber Criminology 17, no. 2 (2023): 133 – 146. https://doi.org/10.5281/zenodo.4766709.
Mutiara, Upik, Ika Khairunnisa Simanjuntak, Rahmad Ramadhan Hasibuan, and A Amiludin. “Exceptions of Banking Secrets for The Interest of Taxes in Indonesia (a Comparation of The Post-Birth of Access Law to Financial Information).” Legality: Jurnal Ilmiah Hukum 28, no. 2 (2020): 196 – 210. https://doi.org/10.22219/ljih.v28i2.13375.
Nazrul, Anija, and Nazrul Islam. Interglobal Competition and Digital Sovereignty: How Firms Build Agility Across Borders. DigiTech Agility for Business Competitiveness and Innovation Imperatives. IGI Global, 2026. https://doi.org/10.4018/979-8-3373-4601-4.ch003.
Nugraha, Yudhistira, Kautsarina, and Ashwin Sasongko Sastrosubroto. “Towards Data Sovereignty in Cyberspace.” In 2015 3rd International Conference on Information and Communication Technology, ICoICT 2015, 465 – 471. Institute of Electrical and Electronics Engineers Inc., 2015. https://doi.org/10.1109/ICoICT.2015.7231469.
Obando, Roberto Ramos, and Pablo Porporatto. “Taxpayer Rights in the Context of the Automatic Exchange of Information (AEOI): Insights from Recent Swiss Case Law.” European Taxation 65, no. 11 (2025): 471 – 478. https://doi.org/10.59403/2seadra.
Olivia, Denindah. “Legal Aspects of Artificial Intelligence on Automated Decision-Making in Indonesia: Lessons from the European Union, the United States, and China.” Lentera Hukum 7, no. 3 (2020): 301 – 318. https://doi.org/10.19184/ejlh.v7i3.18380.
Pongrekun, Dharma, Arfin Sudirman, Widya Setiabudi, and Arry Bainus. “Digital Sovereignty in the Global South: Indonesia’s Cyber Governance between Global Power and National Autonomy.” Research Journal in Advanced Humanities 7, no. 1 (2026). https://doi.org/10.58256/hprs3b27.
Prabowo, Sidik, Maman Abdurohman, Hilal Hudan Nuha, and Sarwono Sutikno. “Identifying and Validating Critical Factors in Designing a Comprehensive Data Protection Impact Assessment (DPIA) Framework for Indonesia.” International Journal of Safety and Security Engineering 15, no. 1 (2025): 113 – 126. https://doi.org/10.18280/ijsse.150113.
Putra, Tegar Islami, W Waspiah, Indriana Firdaus, Fitria Damayanti, and Bintang Rafli Ananta. “Challenges in Ensuring Personal Data Protection for Society in The Era of Society 5.0: Indonesia’s Case Study.” Unnes Law Journal 10, no. 2 (2024): 232 – 254. https://doi.org/10.15294/ulj.v11i2.8928.
Ramadhani, Ressita, Zakka Farisy, and Dina Silvia Puteri. “COMPARATIVE ANALYSIS OF CBDC AND TAX LAW ENFORCEMENT IN SELECTED COUNTRIES.” Journal of Central Banking Law and Institutions 4, no. 1 (2025): 141 – 180. https://doi.org/10.21098/jcli.v4i1.275.
Sayang Bidul, Yeni Widowaty. “Enforcement Of Law Regarding Environmental Damage Due To Mining Activities” 23, no. 2 (2024): 1–13.
Setiawan, Ahmad Budi, and Ashwin Sasongko Sastrosubroto. “Strengthening the Security of Critical Data in Cyberspace, a Policy Review.” In Proceeding - 2016 International Conference on Computer, Control, Informatics and Its Applications: Recent Progress in Computer, Control, and Informatics for Data Science, IC3INA 2016, 185 – 190. Institute of Electrical and Electronics Engineers Inc., 2017. https://doi.org/10.1109/IC3INA.2016.7863047.
Sorrentino, Elisa, Anna Federica Spagnuolo, Alessio Portaro, Maria Taverniti, and Elena Cardillo. “Towards Semantic Coherence: Understanding Cybersecurity and Digital Sovereignty in the Automotive Landscape.” In Proceedings - 2025 IEEE 31st International Symposium on On-Line Testing and Robust System Design, IOLTS 2025. Institute of Electrical and Electronics Engineers Inc., 2025. https://doi.org/10.1109/IOLTS65288.2025.11116851.
Syifaurachman, and Antoni Wibowo. “RISK ASSESSMENT RELATED TO PRIVACY INFORMATION ON ELECTRONIC MONEY SERVER-BASED USING ISO 27001 ISO 27005, ISO 27701.” Journal of Theoretical and Applied Information Technology 101, no. 3 (2023): 1067 – 1077. https://www.scopus.com/inward/record.uri?eid=2-s2.0-85153800017&partnerID=40&md5=98ca981f35cdafb7790e4b1d8f8ef5fe.
Toapanta, Segundo Moisés T, Marjorie Isanoa Sinche, and Luis Enrique Mafla Gallegos. “A Cyber Environment Approach to Mitigate Vulnerabilities and Threats in an Electoral Process in Ecuador.” In ACM International Conference Proceeding Series, 97 – 104. Association for Computing Machinery, 2019. https://doi.org/10.1145/3375900.3375914.
Buku
Hadjon, P. M., dkk. (2005). Pengantar Hukum Administrasi Indonesia. Yogyakarta: Gadjah Mada University Press.
Ibrahim, J. (2008). Teori dan Metodologi Penelitian Hukum Normatif. Malang: Bayu Media Publishing.
Makarim, E. (2017). Konstitusi dan Telematika: Hak dan Kewajiban Konstitusional Terkait Teknologi Informasi dan Komunikasi. Jakarta: Badan Penerbit Fakultas Hukum Universitas Indonesia.
Marzuki, P. M. (2017). Penelitian Hukum. Jakarta: Prenada Media.
OECD. (2012). Keeping it Safe: The OECD Guide on the Protection of Confidentiality of Information Exchanged for Tax Purposes. OECD Publishing. https://doi.org/10.1787/4df278f7-en
OECD. (2017). Standard for Automatic Exchange of Financial Account Information in Tax Matters (2nd ed.). OECD Publishing. https://doi.org/10.1787/9789264267992-en
OECD. (2018). Standard for Automatic Exchange of Financial Information in Tax Matters: Implementation Handbook (2nd ed.). OECD Publishing. https://doi.org/10.1787/841e9512-en
OECD. (2023). International Standards for Automatic Exchange of Information in Tax Matters: Crypto-Asset Reporting Framework and 2023 Update to the Common Reporting Standard. OECD Publishing. https://doi.org/10.1787/896d79d1-en
OECD. (2025). Consolidated Text of the Common Reporting Standard (2025): Standard for Automatic Exchange of Financial Account Information in Tax Matters. OECD Publishing. https://doi.org/10.1787/055664b1-en
OECD. (2025). Peer Review of the Automatic Exchange of Financial Account Information 2025 Update. OECD/Global Forum on Transparency and Exchange of Information for Tax Purposes.
OECD. (2026). Terms of Reference for the Confidentiality and Data Safeguards Assessment. OECD/Global Forum on Transparency and Exchange of Information for Tax Purposes.
Soekanto, S. (1986). Pengantar Penelitian Hukum. Jakarta: Penerbit Universitas Indonesia.
Suhariyanto, B. (2012). Tindak Pidana Teknologi Informasi (Cybercrime): Urgensi Pengaturan dan Celah Hukumnya. Jakarta: RajaGrafindo Persada.
Sumber Hukum
Indonesia. Undang-Undang Nomor 6 Tahun 1983 tentang Ketentuan Umum dan Tata Cara Perpajakan beserta perubahan-perubahannya.
Indonesia. Undang-Undang Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik beserta perubahan-perubahannya.
Indonesia. Undang-Undang Nomor 9 Tahun 2017 tentang Penetapan Peraturan Pemerintah Pengganti Undang-Undang Nomor 1 Tahun 2017 tentang Akses Informasi Keuangan untuk Kepentingan Perpajakan menjadi Undang-Undang.
Indonesia. Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik.
Indonesia. Undang-Undang Nomor 7 Tahun 2021 tentang Harmonisasi Peraturan Perpajakan.
Indonesia. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi.
Indonesia. Peraturan Presiden Nomor 82 Tahun 2022 tentang Pelindungan Infrastruktur Informasi Vital.
Indonesia. Undang-Undang Nomor 1 Tahun 2024 tentang Perubahan Kedua atas Undang-Undang Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik.
Kementerian Keuangan Republik Indonesia. Peraturan Menteri Keuangan Nomor 108 Tahun 2025 tentang Petunjuk Teknis mengenai Akses Informasi Keuangan untuk Kepentingan Perpajakan.
