Skip to navigationSkip to content

Regulatory compliance

Bursa’s compliance with UU PDP, POJK 6/2026, and industry security standards.

Back to overview

Effective: 22 July 2026

If the Indonesian and English versions differ, the Indonesian version governs.

Platform regulatory position

Bursa is a trading-education platform operated under PT Global Makmur Madani - not a financial-services provider (PUJK), broker, or investment adviser. We provide learning infrastructure, not trade execution or personalised investment recommendations. Day-to-day management of Bursanalar is by Raden Mohammad Kaisar Khan and Fakhri Muzakki.

Law No. 27/2022 - Personal Data Protection

AspectBursa implementation
Personal-data controllerPT Global Makmur Madani as controller
Legal bases for processingConsent, contract, legal obligation, legitimate interest
Data-subject rightsRequest form + privacy@bursanalar.com
Data securityTLS, bcrypt, RBAC, audit log
Breach notificationSOP 3�-24 hours to authorities + users
DPOInternal responsible person (also compliance reviewer)

Detail: Privacy Policy.

POJK No. 6/2026 - Finfluencers & financial education

DutyImplementation
No guaranteed profitDisclaimer in Terms, mentor content review
Education is not a recommendationPlatform scope = structured education
Mentor verificationKYC + OJK/Bappebti licences checked before going live
Content complianceCurriculum review before publication

The Platform does not require an OJK PUJK licence because it is not a financial-services offering - but it must still comply as a publisher of financial-education information.

POJK No. 13/2025 - Securities recommendations

Specific buy/sell recommendations require an active Investment Adviser (PI) licence. Bursa:

  • Does not provide platform-level investment recommendations
  • Mentors who give specific recommendations must hold a PI licence
  • A Signal feature (if enabled) is only from PI-licensed mentors

PCI-DSS (payments)

  • Bursa does not store card data (PAN, CVV)
  • Processing via a PCI-DSS certified payment gateway
  • Target scope: SAQ A (hosted payment page)

GDPR-ready

Although the primary focus is UU PDP, we apply GDPR-compatible principles:

  • Data minimisation
  • Privacy by design
  • Right to erasure
  • Data portability (JSON export)

Relevant if the platform accepts international users.

PSE (Electronic System Operator)

Kominfo PSE registration is planned before full-scale public launch.

Pre-launch checklist

  • ToS & Privacy Policy final (counsel review)
  • Mentor Agreement signed
  • PSE registered
  • Payment gateway merchant active
  • POJK 6/2026 content policy enforced
  • DPO designated
  • Penetration test completed