Analisis Privasi Data Pengguna Shopee Berdasarkan Framework ISO 31000:2018

Authors

  • Siti Safira Tawetubun Universitas Muslim Indonesia
  • Satriani Universitasi Muslim Indonesia

Keywords:

E-commerce, ISO 31000, Privasi Data, Shopee

Abstract

The development of e-commerce in Indonesia has increased the risk of personal data leakage and misuse. This research is important because no study has specifically analyzed Shopee's data privacy using an international standard framework. This study aims to identify, analyze, evaluate, and provide risk treatment recommendations for Shopee user data privacy using the ISO 31000:2018 framework. The research method uses a qualitative approach with literature study of Shopee's privacy policy, PDP Law No. 27 of 2022, indexed scientific journals, and online news related to data breach cases. The results identified 8 main risks (R1-R8) including data leakage, account theft, employee access misuse, PDP law violations, ransomware attacks, payment system breaches, data loss due to server crashes, and sale of data to third parties. All risks are at the medium level with scores between 5 and 12 based on frequency multiplied by impact calculation. Mitigation recommendations include end-to-end encryption, mandatory two-factor authentication, formation of a PDP law compliance team, and disaster recovery plan implementation. This research contributes as the first study to combine ISO 31000 with Shopee as the object and focus on user data privacy.

References

T. A. Cahyaaty, I. Wijaya, M. Dafin, and A. Dzky, “Analisis Keamanan Data Pribadi Pada Pengguna E-Commerce Shopee Terhadap Ancaman Data Pribadi,” vol. 5, no. 2, pp. 133–144, 2024, doi: https://doi.org/10.31599/mdpf3g55.

Y. N. Silalahi and M. I. P. Nasution, “Tinjauan Sistem Keamanan Data Pelanggan di E-Commerce: Studi Kasus Platform Shopee,” J. Sist. Informasi, Manaj. dan Teknol. Inf., vol. 3, no. 2, pp. 113–122, 2025, doi: 10.33020/jsimtek.v3i2.813.

D. T. Sonda, “Tinjauan Yuridis Tanggung Jawab Penyelenggara E-Commerce dalam Penyalahgunaan Data Pribadi oleh Pihak Ketiga dalam Transaksi Shopee Pay Later,” Universitas Sumatera Utara, 2024.

“UU No. 27 Tahun 2022.” [Online]. Available: https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022

R. Ayunda, “Personal Data Protection to E-Commerce Consumer: What Are the Legal Challenges and Certainties?,” LAW REFORM, vol. 18, no. 2, pp. 144–163, 2022, doi: 10.14710/lr.v18i2.43307.

A. M. Chaniago, M. Siregar, and J. Arifiyanto, “Perlindungan Hukum Terhadap Data Pribadi Konsumen Dalam Transaksi E-Commerce Shopee,” J. Sci. Soc. Res., vol. 8, no. 1, pp. 184–195, 2025.

I. O. für Normung, ISO 31000: 2018: Risk Management: Guidelines. ISO, 2018.

S. Yakin, T. Hasanuddin, and N. Kurniati, “Application of content based image retrieval in digital image search system,” Bull. Electr. Eng. Informatics, vol. 10, no. 2, pp. 1122–1128, 2021, doi: 10.11591/EEI.V10I2.2713.

A. Setiawan and R. Puspitadewi, “Challenges and Perspectives on Personal Risk Management and Data Privacy in the Indonesian Context,” Rev. Integr. Bus. Econ. Res., vol. 15, p. 3, 2026.

Sulpawati, N. Choirunnisa, and H. F. Rohman, “Strategi Manajemen Risiko Operasional dalam Bisnis E-Commerce untuk Menghadapi Tantangan dan Menemukan Solusi,” J. Manaj. dan Pemasar. ( Jump. ), vol. 4, no. 1, 2025, doi: 10.51771/jumper.v4i1.1729.

E. K. Usmany, “Information Security Planning with Risk Management Using ISO 31000:2018 at E-Commerce XYZ,” J. Inf. Syst. Eng. Manag., vol. 10, no. 33, pp. 75–89, 2025, doi: 10.52783/jisem.v10i33s.5460.

A. P. Kehista et al., “Analisis Keamanan Data Pribadi pada Pengguna E-Commerce: Ancaman, Risiko, Strategi Kemanan (Literature Review),” J. Ilmu Manaj. Terap., vol. 4, no. 5, pp. 625–632, 2023, doi: 10.31933/JIMT.V4I5.1541.

T. Sutabri, Y. Pratama, M. I. Herdiansyah, and W. Cholil, “Information Technology Risk Management Analysis Using COBIT and ISO at Jumputan Industry,” Int. J. Informatics Vis., vol. 9, no. 6, pp. 2418–2429, 2025, doi: 10.62527/JOIV.9.6.3236.

A. Muhammad, C. P. T.W, R. Fauzi, and Pramono, “Efektivitas Platform E-Commerce Dalam Mendukung Bisnis Kaos Anime,” J. Inf. & Comput., vol. 3, no. 1, pp. 21–31, 2025, doi: 10.32493/JICOMISC.V3I1.46981.

G. Stoneburner, A. Goguen, and A. Feringa, “Risk Management Guide for Information Technology Systems,” 2002. doi: https://doi.org/10.6028/NIST.SP.800-30.

A. Ulya, A. Karima, T. S. A. Sukiman, A. Zulfia, and R. Rahmawati, “Information Security Risk Analysis Using ISO 31000:2018 and ISO 27001:2022,” Brill. Res. Artif. Intell., vol. 5, no. 2, pp. 843–853, 2025, doi: 10.47709/brilliance.v5i2.6564.

T. M. Muhtar and E. Radhiansyah, “Analisis Implementasi Kebijakan Perlindungan Data Pribadi dalam Perdagangan Digital di Indonesia Berdasarkan eTrade Readiness Assessment,” J. Integr. Int. Relations, vol. 10, no. 2, pp. 157–179, 2025, doi: 10.15642/jiir.2025.10.2.157-179.

M. M. R. Akbar, K. Yudhistiro, and A. R. Muslikh, “Analysis of Tokopedia Digital Security Strategy Against Cyber Threats Using the Risk Assessment Framework Approach,” J. Innov. Comput. Sci., vol. 4, no. 2, pp. 94–101, 2025, doi: 10.56347/JICS.V4I2.301.

F. S. Lubis, V. S. Praditha, M. Lubis, M. F. Safitra, and Y. Z. Ramadhan, “IT Risk Analysis Based on Risk Management Using ISO 31000: Case study Registration Application at University XYZ,” Proc. 2023 9th Int. Conf. Ind. Bus. Eng., pp. 522–528, 2023, doi: 10.1145/3629378.3629464.

M. Ekania, E. Hamdi, R. Indradewa, and F. Abadi, “Risk Management Planning in E-Commerce Companies PT. SIMPEL OM UNGGULAN "SIMPEL OMâ€,” Syntax Idea, vol. 5, no. 11, pp. 1939–1956, 2023, doi: 10.46799/SYNTAX-IDEA.V5I11.2661.

Downloads

Published

31.07.2026