Reconstructing Taxpayer Data Protection Through a Cyber-Restorative State Accountability Framework
DOI:
https://doi.org/10.46924/jihk.v8i1.495Keywords:
Taxpayer Data, Personal Data Protection, Cyber LawAbstract
The digital transformation of tax administration has significantly improved the efficiency of public services; however, it has also heightened the risk of taxpayer data breaches involving highly sensitive personal and financial information. This study aims to examine the legal status of taxpayer data, identify the fragmentation of the regulatory framework governing taxpayer data protection, analyze state responsibility from a cyber law perspective, and develop a cyber-restorative state accountability framework. The research employs a normative legal methodology using statutory, conceptual, and comparative approaches. Data are analyzed prescriptively through systematic legal interpretation. The findings indicate that taxpayer data simultaneously constitute specific personal data, confidential tax information, and electronic information, each protected under multiple legal regimes. Nevertheless, the existing regulatory framework remains fragmented, resulting in inconsistencies in legal protection and state accountability. To address these shortcomings, this study proposes a cyber-restorative state accountability framework that integrates preventive measures, cybersecurity governance, breach notification, incident investigation, data recovery, and compensation mechanisms. The study concludes that reconstructing the legal framework based on this model is essential for strengthening legal certainty, enhancing state accountability, and fostering public trust in digital tax administration.
Downloads
References
Journals
Acev, David, Sankalp Biyani, Florian Rieder, et al. “Systematic Analysis of Data Governance Frameworks and Their Relevance to Data Trusts.” Management Review Quarterly, ahead of print, July 31, 2025. https://doi.org/10.1007/s11301-025-00545-1.
Aghna, Naura Atania Putri. “Kepastian Hukum Keamanan Data Pribadi Wajib Pajak Dalam Pembayaran Pajak Secara Digital.” Jurnal Hukum Indonesia 5, no. 2 (2026): 165–73. https://doi.org/10.58344/jhi.v5i2.2530.
Alatas, Hamzah Haikal Riziq Alwi, and Gunawan Djajaputra. “Examining Indonesian Government Accountability And Mitigation Measures In The 2024 Taxpayer Identification Number Data Breach.” Jurnal Ilmu Hukum Kyadiren 7, no. 2 (2025): 1234–48. https://doi.org/10.46924/jihk.v7i2.385.
Chircop, Luke. “A Due Diligence Standard of Attribution in Cyberspace.” International and Comparative Law Quarterly 67, no. 3 (2018): 643–68. https://doi.org/10.1017/S0020589318000015.
Dirgantara, Febrian, Dharma Setiawan Negara, Didit Darmawan, Endra Andie Aryanto, and Alwi Mohamad Shahab. “Legal Responsibility of Companies in Cases of Personal Data Breaches.” Innovative: Journal of Social Science Research 5, no. 1 (2025): 5053–65. https://doi.org/10.31004/innovative.v5i1.18046.
Huda, Uu Nurul, Tatang Astarudin, Muhammad Irsan Nasution, Ahmad Abdul Khozin, and Muhammad Irsan. “Legal Protection for Personal Data Leaks and Its Implications for Citizens’ Privacy Rights Within The Framework of The Indonesian Legal State.” Jambura Law Review 1, no. 1 (2026): 144–59. https://doi.org/10.33756/jlr.v1i1.32666.
Judijanto, Loso. “Protection of Taxpayer Personal Data in Tax Administration: A Review.” Digital Business: Tren Bisnis Masa Depan 15, no. 3 (2024): 185–94.
Nurmala, Salma Ayu, and Sidi Ahyar Wiraguna. “Analisis Yuridis Tanggung Jawab Direktorat Jenderal Pajak (DJP) Terhadap Kebocoran Data Nomor Pokok Wajib Pajak (NPWP) Berdasarkan Undang-Undang Nomor 27 Tahun 2022.” Jurnal Kajian Ilmiah 26, no. 1 (2026): 85–94. https://doi.org/10.31599/207r0b59.
Satoto, Endro, and Faisal Santiago. “Reconstruction of Indonesia’s Cyber Law System for Adaptive and Integrated Digital Crime Prevention in the Era of Technological Disruption.” Greenation International Journal of Law and Social Sciences 3, no. 2 (2025): 309–17. https://doi.org/10.38035/gijlss.v3i2.425.
“The State’s Positive Obligation to Ensure Personal Data Protection.” GRUR International 74, no. 5 (2025): 501–4. https://doi.org/10.1093/grurint/ikaf018.
Widayanti, Tri Fenny, Aditya Dwi Rohman, A. Nuril Zamharir Haris, Eka Merdekawati Djafar, and Muhammad Zulfan Hakim. “Enhancing Cybersecurity and Legal Integration: Reforming Indonesia’s Cyber Law to Foster Sustainable Growth in the Digital Economy.” Diponegoro Law Review 10, no. 1 (2025): 105–19. https://doi.org/10.14710/dilrev.10.1.2025.105-119.
Zhang, Yanlei. “Data Breach Disclosure Laws and Corporate Tax Planning Activities.” Journal of International Accounting, Auditing and Taxation 60 (2026): 100749. https://doi.org/10.1016/j.intaccaudtax.2026.100749.
Proceedings
Alfajri, Farhan Zaidan, and Fatma Ulfatun Najicha. “Legal Reconstruction of Accountability for the Security of Electronic-Based Government Systems Based on the Principles of Good Governance.” In Proceedings of the International Conference on Democracy and National Resilience 2025 (ICDNR 2025), vol. 981, edited by Sunny Ummul Firdaus, Gayatri Dyah Suprobowati, R. Prihandjojo Andri Putranto, et al. Advances in Social Science, Education and Humanities Research. Atlantis Press SARL, 2025. https://doi.org/10.2991/978-2-38476-529-4_12.
Books
Lessig, Lawrence. Code: And Other Laws of Cyberspace. Basic Books, 1999.
Mertokusumo, Sudikno. Penemuan Hukum: Sebuah Pengantar. 6th ed. Liberty, 2009.
Rahayu, Siti Kurnia. Keamanan Digital Dalam Audit Pajak: Integrasi Cyber Security Dengan CRM, BDA, Dan BI Untuk Revolusi Compliance. Unikom Press, 2024.
Webpages
Marwah, Hanin. “6 Juta Data NPWP Bocor: Diduga Milik Jokowi, Sri Mulyani, Dan Zulhas, Diperjualbelikan Seharga Rp 152 Juta.” Tempo, 2024. https://www.tempo.co/ekonomi/6-juta-data-npwp-bocor-diduga-milik-jokowi-sri-mulyani-dan-zulhas-diperjualbelikan-seharga-rp-152-juta-8164.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Imam Cahyo Pornomo, Ismiyanto Ismiyanto, Hafid Zakariya

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Copyright on any article is retained by the author(s).
- The author grants the journal, the right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgment of the work’s authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal’s published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.
- The article and any associated published material is distributed under the Creative Commons Attribution 4.0 International License


Sinta ID: 














