Mapping Compliance–Maturity Gaps in EdTech Personal Data Security: Integrating the PDP Law and KAMI Index 5.0

Authors

  • Ocha Oktafia Cyber Security Engineering, Politeknik Negeri Batam
  • Nelmiawati Nelmiawati Cyber Security Engineering, Politeknik Negeri Batam
  • Putri Hening Graha Public Policy, National University of Singapore
  • Kessy Dealova Cyber Security Engineering, Politeknik Negeri Batam

DOI:

https://doi.org/10.30871/jaic.v10i4.13447

Keywords:

EdTech, ISO/IEC 27002:2022, KAMI 5.0 Index, PDP Law

Abstract

The rapid post-pandemic growth of Educational Technology (EdTech) platforms in Indonesia is not always accompanied by personal data security readiness, despite the high compliance demands mandated by Law Number 27 of 2022 concerning Personal Data Protection (PDP Law). Previous studies utilizing the KAMI Index generally assessed technical maturity separately from legal frameworks, leaving a gap in understanding how regulatory compliance correlates with technical maturity within a single entity. This study aims to evaluate the information security maturity level and legal compliance of PT XYZ's EdTech platform, while simultaneously mapping the connection between the PDP Law requirements and the assessment areas of KAMI Index 5.0. This research employs a qualitative case study approach. Data were collected through questionnaires based on the KAMI Index 5.0 instrument and PDP Law articles, completed by three key respondents—the CEO, CTO, and VP of Information Security—and subsequently validated through interviews and verification of supporting documents. The results reveal a significant gap: procedural compliance with the PDP Law is relatively high (28 out of 36 articles fully implemented), yet the KAMI Index maturity level falls into the "Inadequate" (Tidak Layak) category with a final score of 222. The system is notably weak in risk management and personal data protection areas (Level I+). These findings emphasize that procedural compliance does not equate to holistic security maturity. This research contributes by providing a legal-technical gap mapping alongside recommendations based on ISO/IEC 27002:2022, which can be adopted by other EdTech organizations.

Downloads

Download data is not yet available.

References

[1] D. Kim, K. Borowiec, and S. Wortham, “A New Era in EdTech: Emerging Challenges and Opportunities,” ECNU Review of Education, vol. 7, no. 2, 2023, doi: 10.1177/20965311231200510.

[2] Badan Siber dan Sandi Negara, "Laporan Landscape Keamanan Siber Indonesia 2023," Jakarta, Badan Siber dan Sandi Negara, 2023. [Online]. Available: https://www.bssn.go.id/wp-content/uploads/2024/03/Lanskap-Keamanan-Siber-Indonesia-2023.pdf. [Accessed: Oct. 5, 2024].

[3] A. Zeyab and G. M. Alayyar, “Perspective Chapter: Education Technology (EdTech) and the Online Course Revolution,” IntechOpen, 2023, doi: 10.5772/intechopen.109227.

[4] A. S. Al-Sherideh, K. Maabreh, M. Maabreh, M. R. A. Mousa, and M. Asassfeh, "Assessing the impact and effectiveness of cybersecurity measures in e-learning on students and educators: A case study," Int. J. Adv. Comput. Sci. Appl., vol. 14, no. 5, p. 159, 2023.

[5] Q. Liu and M. Khalil, “Understanding privacy and data protection issues in learning analytics using a systematic review,” Br. J. Educ. Technol., vol. 54, no. 6, pp. 1–33, Sep. 2023, doi: 10.1111/bjet.13388.

[6] A. A. Rahman, A. Marwan, and A. T. Haryono, "The readiness for privacy compliance in Indonesia before October 2024," Int. J. Soc. Sci. Human. Res., vol. 7, no. 8, pp. 6154-6155, 2024, doi: 10.47191/ijsshr/v7-i08-41.

[7] E. P. Maheswari and S. A. Wiraguna, “Urgensi Persetujuan Pemilik Data dalam Pengelolaan Data Pribadi oleh Platform Digital”, JIKSP, vol. 2, no. 4, pp. 908–914, 2025. [Online]. Available: http://jurnal.ittc.web.id/index.php/jiksp/article/view/2498.

[8] H. H. Samin, “Perlindungan hukum terhadap kebocoran data pribadi oleh pengendali data melalui pendekatan hukum progresif,” J. Ilm. Res. Student, vol. 1, no. 3, 2023, doi: 10.61722/jssr.v1i3.386.

[9] Undang-Undang Republik Indonesia, “Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi”, Jakarta: Presiden Republik Indonesia, 2022.

[10] Tim Pengukuran Tingkat Kematangan Keamanan Siber dan Sandi, "Pedoman Pengisian Instrumen Indeks KAMI v5.0 Pemerintah Daerah," Direktorat Keamanan Siber dan Sandi Pemerintah Daerah, Deputi Bidang Keamanan Siber dan Sandi Pemerintahan dan Pembangunan Manusia, Badan Siber dan Sandi Negara (BSSN), Revisi 2.0, Apr. 2025.

[11] K. Wasilah, M. S. H. Kurniawan, and Firmansyah, "Evaluasi Tingkat Keamanan Informasi Pada Dinas Kominfo Lampung Selatan Menggunakan Indeks Kami 4.3," Jurnal Ilmu Komputer Agri-informatika, vol. 11, no. 1, pp. 13–18, 2022. [Online]. Available: https://journal.ipb.ac.id/index.php/jika.

[12] H. I. Azmi, M. T. Akbar, B. T. Kumala Dewi, and B. Sugiantoro, "Evaluasi Tingkat Kesiapan Keamanan Informasi Pada SMK XYZ Menggunakan Indeks KAMI Versi 4.2," CyberSecurity dan Forensik Digital, vol. 7, no. 1, pp. 42–49, 2024, doi: 10.14421/csecurity.2024.7.1.4422.

[13] M. S. Jenny, R. N. Shofa, and A. Rahmatulloh, "Analisis Tingkat Kesiapan Keamanan Informasi Menggunakan Keamanan Informasi (Indeks KAMI) Versi 4.2 Pada Sistem Informasi Akademik (SIMAK) Universitas Siliwangi," Jurnal Sistem Informasi dan Teknologi, vol. 7, no. 1, pp. 1-10, 2024, doi: 10.24176/sitech.v7i1.12390.

[14] D. I. Khamil, G. M. A. Sasmita, and A. A. H. Susila, "Evaluasi Tingkat Kesiapan Keamanan Informasi Menggunakan Indeks Kami 4.2 Dan ISO/IEC 27001:2013 (Studi Kasus: Diskominfo Kabupaten Gianyar)," Jurnal Teknik Informatika dan Sistem Informasi, vol. 9, no. 3, pp. 1948–1960, 2022, doi: 10.35957/jatisi.v9i3.2310.

[15] S. Yuliani, N. T. Ramadhini, A. I. Gustisyaf, and A. Wahyudin, "Asesmen Keamanan Informasi Menggunakan Indeks KAMI," NARATIF (Jurnal Ilmiah Nasional Riset Aplikasi dan Teknik Informatika), vol. 2, no. 1, pp. 1-10, 2020, doi: 10.53580/naratif.v2i1.76.

[16] M. Rizkillah, "Evaluasi Keamanan Informasi Perguruan Tinggi Menggunakan Indeks Keamanan Informasi (KAMI) Versi 5.0," Jurnal Cakrawala Ilmiah, vol. 3, no. 10, pp. 1-10, 2024, doi: 10.54099/jci.v3i10.7988.

[17] L. D. A. Jelita, M. N. A. Azam, and A. Nugroho, "Evaluasi Keamanan Teknologi Informasi Menggunakan Indeks Keamanan Informasi 5.0 dan ISO/EIC 27001:2022," Jurnal Saintekom: Sains, Teknologi, Komputer dan Manajemen, vol. 14, no. 1, pp. 84–94, 2024, doi: 10.33020/saintekom.v14i1.623.

[18] A. L. Maryanto, M. N. A. Azam, and A. Nugroho, "Evaluasi Manajemen Keamanan Informasi Pada Perusahaan Pemula Berbasis Teknologi Menggunakan Indeks KAMI," Jurnal Simantec, vol. 11, no. 1, pp. 1-10, 2022, doi: 10.21107/simantec.v11i1.14099.

[19] S. F. Rahayu, D. Prawira, and I. Rusi, "Pengukuran Tingkat Keamanan Informasi Menggunakan Metode Indeks KAMI (Studi Kasus: Dinas Komunikasi dan Informatika Kota Pontianak)," Jurnal Komputer dan Aplikasi, vol. vol. 9, no. 3, pp. 468–477, 2021, doi: 10.26418/coding.v9i03.51126.

[20] D. Saputra, R. Y. Rahman, M. S. Hasibuan, and G. J. H. Aziz, "Penilaian Tingkat Kesiapan Keamanan Informasi Pada Dinas Kominfo Kabupaten XYZ dengan Indeks KAMI Versi 4.2," Jurnal Ilmu Komputer, Sistem Informasi, Teknik Informatika, vol. 2, no. 2, pp. 1–10, Sep. 2023. [Online]. Available: https://jurnal.akommedia.net/index.php/JILKOMSITI/article/view/31.

[21] O. Tajik, J. Golzar, and S. Noor, “Purposive Sampling,” Int. J. Educ. Lang. Stud., vol. 2, no. 2, pp. 85–92, 2024, doi: 10.59569/ijels.v2i2.411.

[22] J. Ani, B. Lumanauw, and J. L. A. Tampenawas, "Pengaruh citra merek, promosi dan kualitas layanan terhadap keputusan pembelian konsumen pada e-commerce Tokopedia di Kota Manado," J. EMBA, vol. 10, no. 1, pp. 667–676, 2022, doi: 10.35794/emba.v10i1.38279.

[23] B. S. Wibowo and R. F. Aji, "Rekomendasi implementasi 11 kontrol keamanan informasi baru ISO/IEC 27001:2022 di perusahaan HealthTech XYZ," The Indonesian Journal of Computer Science, vol. 13, no. 4, pp. 315–325, 2024, doi: 10.33022/ijcs.v13i4.4166.

[24] K. S. A. Fajri and R. Harwahyu, “Information Security Management System Assessment Model by Integrating ISO 27002 and 27004”, MALCOM, vol. 4, no. 2, pp. 498-506, Feb. 2024.

Downloads

Published

2026-08-12

How to Cite

[1]
O. Oktafia, N. Nelmiawati, P. H. Graha, and K. Dealova, “Mapping Compliance–Maturity Gaps in EdTech Personal Data Security: Integrating the PDP Law and KAMI Index 5.0”, JAIC, vol. 10, no. 4, pp. 3808–3814, Aug. 2026.

Similar Articles

<< < 1 2 3 4 5 > >> 

You may also start an advanced similarity search for this article.