Privacy and Security Risks in Cross-Border Digital Payment Systems

Authors

  • Naeem AllahRakha Department of Cyber Law, Tashkent State University of Law, Uzbekistan
  • Tillayeva Gulsanam Xamdamovna Department of Social and Humanitarian Science, Tashkent State Agrarian University, Uzbekistan
  • Bozarov Sardor Sokhibjonovich Department of Cyber Law, Tashkent State University of Law, Uzbekistan
  • Otabek Narziev Department of Cyber Law, Tashkent State University of Law, Uzbekistan
  • Pulatov Temurbek Department of Cyber Law, Tashkent State University of Law, Uzbekistan

DOI:

https://doi.org/10.22219/ljih.v33i2.40400

Keywords:

Cross-Border Digital Payments; Data Governance; Privacy and Security Risks; Regulatory Frameworks; User Rights and Protections

Abstract

This research examines the privacy and security concerns associated with the growing adoption of digital payments. Digital payments represent a new development in payment systems being assessed by institutions, companies, and individuals. The worldwide adoption of digital payments necessitates a thorough examination of the privacy and security risks associated with these systems, particularly those operating under different regulatory frameworks. This research identifies gaps in current laws and major weaknesses in privacy and security protections, with a focus on risks to user rights. Using a mixed-methods approach, the study includes a qualitative analysis of relevant data protection laws along with a quantitative survey of user concerns and awareness. It examines practical issues and combines insights using grounded theory. The findings indicate a heavy dependence on central regulation and varying privacy standards, resulting in more frequent violations that restrict user protections and avenues for recourse. This research suggests establishing global privacy and security standards for digital payments, supported by strong enforcement and collaboration between countries. These standards should provide clear data practices, give users control over their personal information, implement robust security measures, and encourage the use of new technologies that enhance privacy. The study concludes that careful governance and cooperation are crucial for the safe development of cross-border digital payment systems, while mitigating risks to privacy, security, and user rights.

Downloads

Download data is not yet available.

References

Aditya, Z. F., & Al-Fatih, S. (2021). Indonesian constitutional rights: expressing and purposing opinions on the internet. The International Journal of Human Rights, 25(9), 1395-1419. https://doi.org/10.1080/13642987.2020.1826450.

Ahmed, H., & Ibrahim, I. R. (2018). Financial consumer protection regime in Malaysia: Assessment of the legal and regulatory framework. Journal of Consumer Policy, 41(2), 159–175. https://doi.org/10.1007/s10603-018-9369-0

Akanfe, O., Valecha, R., & Rao, H. R. (2020a). Assessing country-level privacy risk for digital payment systems. Computers & Security, 99, 102065. https://doi.org/10.1016/j.cose.2020.102065

Akanfe, O., Valecha, R., & Rao, H. R. (2020b). Assessing country-level privacy risk for digital payment systems. Computers & Security, 99, 102065. https://doi.org/10.1016/j.cose.2020.102065

Aldboush, H. H. H., & Ferdous, M. (2023). Building Trust in Fintech: An Analysis of Ethical and Privacy Considerations in the Intersection of Big Data, AI, and Customer Trust. International Journal of Financial Studies, 11(3), 90. https://doi.org/10.3390/ijfs11030090

AlHares, A., Zaerinajad, Z., & Al Bahr, M. (2024). Customer awareness and cyber security in the Organisation for Economic Co-operation and Development countries. Corporate and Business Strategy Review, 5(1, special Issue), 371–381. https://doi.org/10.22495/cbsrv5i1siart11

AllahRakha, N. (2024). The Legality of Reverse Engineering and the Protection of Trade Secrets in the Software Industry. Jurisdictie: Jurnal Hukum dan Syariah, 15 (2), 309-334. http://dx.doi.org/10.18860/j.v15i2.28422

AllahRakha, N. (2025). Executive Discretion in Sports Awards: A Case Study of Pakistan’s Olympians. Cogent Social Science, 11(1), 2534414. https://doi.org/10.1080/23311886.2025.2534414

AllahRakha, N. (2025). Legislators’ qualifications in Pakistan under Islamic constitutional provisions. Journal of Human Rights, Culture and Legal System, 5(2). https://doi.org/10.53955/jhcls.v5i2.491

Andreas Klug. (2016). Briefing Note: Worldpay’s General Approach to Privacy and EU GDPR Implementation. https://ideas-global.org/wp-content/uploads/2018/05/External-overview-of-GDPR-strategy-for-customer-use.pdf

Andrew Burt. (2023, May 16). The Digital World Is Changing Rapidly. Your Cybersecurity Needs to Keep Up. Harvard Law Review. https://hbr.org/2023/05/the-digital-world-is-changing-rapidly-your-cybersecurity-needs-to-keep-up

Akanfe, O., Valecha, R., & Rao, H. R. (2020). Assessing country-level privacy risk for digital payment systems. Computers & Security, 99, 102065. https://doi.org/10.1016/j.cose.2020.10206

Andy Schmulow, Therese Wilson, Nicola Howell, Nina Reynolds, & Paul Mazzola. (2021). Treating Customers Fairly. A concept. A framework. An alternative? Australian Law Reform Commission Review of the Legislative Framework for Corp. https://www.alrc.gov.au/wp-content/uploads/2023/09/Consumer-Experiences-in-Financial-Services-Results.pdf

Arora, N., & Zinolabedini, D. (2023). The Ethical Implications of the 2018 Facebook-Cambridge Analytica Data Scandal. The University of Texas at Austin. http://dx.doi.org/10.26153/tsw/7590

Arslan But, Pakeeza Tabassum, & Farhat Saeed Imran. (2023). Exploring The Mesopotamian Trade (C.6000-539 Bce): Types, Organization, And Expansion. PalArch’s Journal Of Archaeology Of Egypt/Egyptology, 20(1), 241–261. https://archives.palarch.nl/index.php/jae/article/view/11691

Auñón, J. M., Hurtado-Ramírez, D., Porras-Díaz, L., Irigoyen-Peña, B., Rahmian, S., Al-Khazraji, Y., Soler-Garrido, J., & Kotsev, A. (2024). Evaluation and utilisation of privacy enhancing technologies—A data spaces perspective. Data in Brief, 55, 110560. https://doi.org/10.1016/j.dib.2024.110560

Ayatulloh Michael Musyaffi, Etty Gurendrawati, Bambang Afriadi, Mario Colega Oli, & Yuni Widawati, R. O. (2022). Resistance of Traditional SMEs in Using Digital Payments: Development of Innovation Resistance Theory. Human Behavior and Emerging Technologies. https://doi.org/10.1155/2022/7538042

Beduschi, A. (2019). Digital identity: Contemporary challenges for data protection, privacy and non-discrimination rights. Big Data & Society, 6(2), 205395171985509. https://doi.org/10.1177/2053951719855091

Bénétrix, A., Gautam, D., Juvenal, L., & Schmitz, M. (2020). Cross-Border Currency Exposures: New Evidence Based on an Enhanced and Updated Dataset. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.3611655

Bimantara, A., & Nugraha, R. T. (2025). The politics of international cooperation in cross-border digital payment connectivity: A case study of QR payment system in ASEAN. Sospol, 11(1), 82–99. https://doi.org/10.22219/jurnalsospol.v11i1.38367

Bradford, L., Aboy, M., & Liddell, K. (2021). Standard contractual clauses for cross-border transfers of health data after Schrems II. Journal of Law and the Biosciences, 8(1). https://doi.org/10.1093/jlb/lsab007

Coche, E., Kolk, A., & Ocelík, V. (2024). Unravelling cross-country regulatory intricacies of data governance: the relevance of legal insights for digitalization and international business. Journal of International Business Policy, 7(1), 112–127. https://doi.org/10.1057/s42214-023-00172-1

Cremer, F., Sheehan, B., Fortmann, M., Kia, A. N., Mullins, M., Murphy, F., & Materne, S. (2022). Cyber risk and cybersecurity: A systematic review of data availability. The Geneva Papers on Risk and Insurance - Issues and Practice, 47(3), 698–736. https://doi.org/10.1057/s41288-022-00266-6

Cymone Gosnell. (2019). The General Data Protection Regulation: American Compliance Overview and the Future of the American Business. Journal of Business & Technology Law, 15(1). https://digitalcommons.law.umaryland.edu/jbtl/vol15/iss1/6

Daniel Tolstoy, Emilia Rovira Nordman, Sara Melén Hånell, & Nurgül Özbek. (2021). The development of international e-commerce in retail SMEs: An effectuation perspective. Journal of World Business, 56(3). https://doi.org/10.1016/j.jwb.2020.101165

David W. Opderbeck. (2023). Cybersecurity and Data Breach Harms: Theory and Reality. Maryland Law Review, 82(4). https://digitalcommons.law.umaryland.edu/mlr/vol82/iss4/4

De’, R., Pandey, N., & Pal, A. (2020). Impact of digital surge during Covid-19 pandemic: A viewpoint on research and practice. International Journal of Information Management, 55, 102171. https://doi.org/10.1016/j.ijinfomgt.2020.102171

Dilip Ratha. (2023). Remittances: Funds for the Folks Back Home. IMF. https://www.imf.org/en/Publications/fandd/issues/Series/Back-to-Basics/Remittances

Dinçkol, D., Ozcan, P., & Zachariadis, M. (2023). Regulatory standards and consequences for industry architecture: The case of UK Open Banking. Research Policy, 52(6), 104760. https://doi.org/10.1016/j.respol.2023.104760

Dorfleitner, G., Hornuf, L., & Kreppmeier, J. (2023). Promise not fulfilled: FinTech, data privacy, and the GDPR. Electronic Markets, 33(1), 33. https://doi.org/10.1007/s12525-023-00622-x

Engström, E., Eriksson, K., Björnstjerna, M., & Strimling, P. (2023). Global variations in online privacy concerns across 57 countries. Computers in Human Behavior Reports, 9, 100268. https://doi.org/10.1016/j.chbr.2023.100268

Esteban Ortiz-Ospina, Diana Beltekian, & Max Roser. (2024, April). Trade and Globalization. Our World In Data. https://ourworldindata.org/trade-and-globalization

Fahad, & Shahid, M. (2022). Exploring the determinants of adoption of Unified Payment Interface (UPI) in India: A study based on diffusion of innovation theory. Digital Business, 2(2), 100040. https://doi.org/10.1016/j.digbus.2022.100040

Fatima, R., Yasin, A., Liu, L., Wang, J., Afzal, W., & Yasin, A. (2019). Sharing information online rationally: An observation of user privacy concerns and awareness using serious game. Journal of Information Security and Applications, 48, 102351. https://doi.org/10.1016/j.jisa.2019.06.007

Ferrari, M. V. (2022). The platformisation of digital payments: The fabrication of consumer interest in the EU FinTech agenda. Computer Law & Security Review, 45, 105687. https://doi.org/10.1016/j.clsr.2022.105687

Ferreira, A., & Sandner, P. (2021). Eu search for regulatory answers to crypto assets and their place in the financial markets’ infrastructure. Computer Law & Security Review, 43, 105632. https://doi.org/10.1016/j.clsr.2021.105632

Florencia Marotta-Wurgler. (2016). Self-Regulation and Competition in Privacy Policies. The Journal of Legal Studies, 45(S), 13–39. https://chicagounbound.uchicago.edu/jls/vol45/iss3/2

Goyeneche, D., Singaraju, S., & Arango, L. (2024). Linked by age: a study on social media privacy concerns among younger and older adults. Industrial Management & Data Systems, 124(2), 640–665. https://doi.org/10.1108/IMDS-07-2023-0462

Hillman, S., Neustaedter, C., Oduor, E., & Pang, C. (2014). User challenges and successes with mobile payment services in North America. Proceedings of the 16th International Conference on Human-Computer Interaction with Mobile Devices & Services, 253–262. https://doi.org/10.1145/2628363.2628389

Hoofnagle, C. J., King, J., Li, S., & Turow, J. (2010). How Different are Young Adults from Older Adults When it Comes to Information Privacy Attitudes and Policies? SSRN Electronic Journal. https://doi.org/10.2139/ssrn.1589864

Hu, K., Gong, S., Zhang, Q., Seng, C., Xia, M., & Jiang, S. (2024). An overview of implementing security and privacy in federated learning. Artificial Intelligence Review, 57(1), 204. https://doi.org/10.1007/s10462-024-10754-9

Ibrahim Niankara, & Rachidatou I. Traoret. (2023). The digital payment-financial inclusion nexus and payment system innovation within the global open economy during the COVID-19 pandemic. Journal of Open Innovation: Technology, Market, and Complexity, 9(4). https://doi.org/10.1016/j.joitmc.2023.100173

Irini Kanaris Miyashiro. (2021). Case Study: Equifax Data Breach. Seven Pillars Institute. https://sevenpillarsinstitute.org/case-study-equifax-data-breach/

Jan Hogendorn, & Marion Johnson. (2003). THE SHELL MONEY OF THE SLAVE TRADE. Cambridge University Press. https://doi.org/10.1017/CBO9780511563041

Joanne K. McQuilty. (2020). The Privacy Paradox: An Investigation of Smart Applications, Social Relations and Privacy. University of Wollongong. https://ro.uow.edu.au/articles/thesis/The_Privacy_Paradox_An_Investigation_of_Smart_Applications_Social_Relations_and_Privacy/27667086?file=50387322

John Pickering. (1844). The History of Paper Money in China. Journal of the American Oriental Society, 1(2), 136–142. https://doi.org/10.2307/3217743

John Rothchild. (1999). Protecting the Digital Consumer: The Limits of Cyberspace Utopianism. Indiana Law Journal, 74(3). https://www.repository.law.indiana.edu/ilj/vol74/iss3/5

Jong-Hyuok Jung, Eunseon Kwon, & Dong Hoo Kim. (2020). Mobile payment service usage: U.S. consumers’ motivations and intentions. Computers in Human Behavior Reports, 1. https://doi.org/10.1016/j.chbr.2020.100008

Juliussen, B. A., Kozyri, E., Johansen, D., & Rui, J. P. (2023). The third country problem under the GDPR: enhancing protection of data transfers with technology. International Data Privacy Law, 13(3), 225–243. https://doi.org/10.1093/idpl/ipad013

Jun Yong Xiang, & Jing Linbo. (2021). Electronic Commerce in China: Current Status, Development Strategies, and New Trends. China Finance and Economic Review, 3(3), 71–94. https://www.degruyterbrill.com/journal/key/cfer/3/3/html?srsltid=AfmBOoqTTkTrlIagVFDOm9K7B8xY9Y4nh39I3QFWMuYKDbjBnH_SYL_9#issuesInVolume

Karoly, P. (1993). Mechanisms of Self-Regulation: A Systems View. Annual Review of Psychology, 44(1), 23–52. https://doi.org/10.1146/annurev.ps.44.020193.000323

Kaur, G. (2024). Privacy implications of central bank digital currencies (CBDCs): A systematic review of literature. EDPACS, 69(9), 87–123. https://doi.org/10.1080/07366981.2024.2376794

Khando Khando, M. Sirajul Islam, & Shang Gao. (2023). The Emerging Technologies of Digital Payments and Associated Challenges: A Systematic Literature Review. Future Internet, 15(1). DOI:10.3390/fi15010021

Krishna, B., Krishnan, S., & Sebastian, M. P. (2023). Understanding the process of building institutional trust among digital payment users through national cybersecurity commitment trustworthiness cues: a critical realist perspective. Information Technology & People. https://doi.org/10.1108/ITP-05-2023-0434

Kurt Knutsson. (2023, May 29). The dark side of PayPal and how to stay safe. Fox News. https://www.foxnews.com/tech/dark-side-paypal-stay-safe

L. Randall Wray. (1999). The Origins of Money and the Development of the Modern Financial System. https://doi.org/10.1057/9781137539922

Law, J. (2025). 11: Singapore payment services. In Payment services. Edward Elgar Publishing. https://doi.org/10.4337/9781035332878.00019

Leora Klapper. (2023). How digital payments can benefit entrepreneurs. IZA World of Labor. https://wol.iza.org/uploads/articles/648/pdfs/how-digital-payments-can-benefit-entrepreneurs.pdf

Linh, T. T. (2025). Adoption of digital payment methods in Vietnam: Key determinants and distribution analysis. Journal of Distribution Science, 23(2), 39–49. https://doi.org/10.15722/JDS.23.02.202502.39

Lowry, P. B., Wells, T. M., Moody, G., Humpherys, S., & Kettles, D. (2006). Online Payment Gateways Used to Facilitate E-Commerce Transactions and Improve Risk Management. Communications of the Association for Information Systems, 17. https://doi.org/10.17705/1CAIS.01706

McKay Smith, & Garrett Mulrain. (2018). Equi-Failure: The National Security Implications of the Equifax Hack and a Critical Proposal for Reform. JOURNAL OF NATIONAL SECURITY LAW & POLICY, 9, 549–588. https://nationalsecurity.law.georgetown.edu/journal/2018/07/11/equi-failure-the-national-security-implications-of-the-equifax-hack-and-a-critical-proposal-for-reform/

Michael Peneder. (2022). Digitization and the evolution of money as a social technology of account. Journal of Evolutionary Economics, 32, 175–203. https://doi.org/10.1007/s00191-021-00729-4

Michele Braun, James McAndrews, William Roberds, & Richard Sullivan. (2008). Understanding Risk Management in Emerging Retail Payments. FRBNY Economic Policy Review, 137–159. https://www.newyorkfed.org/medialibrary/media/research/epr/08v14n2/0809brau.pdf

Naeem AllahRakha. (2024). Demystifying the Network and Cloud Forensics’ Legal, Ethical, and Practical Considerations. Pakistan Journal of Criminology, 16(2), 119–132. https://doi.org/10.62271/pjc.16.2.119.132

Parma Bains, & Caroline Wu. (2023). Institutional Arrangements for Fintech Regulation: Supervisory Monitoring (NOTE/2023/004).

https://doi.org/10.5089/9798400245664.063

Praveen Shanmugalingam, Ahashraaj Shanmuganeshan, Abinaya Manorajan, Mathusany Kugathasan, & Geethma Yahani Pathirana. (2023). Does e-commerce really matter on international trade of Asian countries: Evidence from panel data. PLOSEONE. https://doi.org/10.1371/journal.pone.0284503

Putrevu, J., & Mertzanis, C. (2024a). The adoption of digital payments in emerging economies: challenges and policy responses. Digital Policy, Regulation and Governance, 26(5), 476–500. https://doi.org/10.1108/DPRG-06-2023-0077

Putrevu, J., & Mertzanis, C. (2024b). The adoption of digital payments in emerging economies: challenges and policy responses. Digital Policy, Regulation and Governance, 26(5), 476–500. https://doi.org/10.1108/DPRG-06-2023-0077

Rachman, A., Julianti, N., & Arkoyah, S. (2024). Challenges and opportunities for QRIS implementation as a digital payment system in Indonesia. EkBis: Jurnal Ekonomi Dan Bisnis, 8(1), 1–13. https://doi.org/10.14421/EkBis.2024.8.1.2134

Raikar, S., & Adamson, S. (2020). Renewable project finance structures and risk allocation. In Renewable Energy Finance (pp. 55–66). Elsevier. https://doi.org/10.1016/B978-0-12-816441-9.00005-2

Regulatory and Policy Gaps and Inconsistencies of Digital Currencies (2/8 Digital Currency Governance Consortium White Paper Series). (2021). https://www3.weforum.org/docs/WEF_Regulatory_and_Policy_Gaps_2021.pdf

Rizka Ramayanti, Nurul Aisyah Rachmawati, Zubir Azhar, & Nik Hadiyan Nik Azman. (2024). Exploring intention and actual use in digital payments: A systematic review and roadmap for future research. Computers in Human Behavior Reports, 13. https://doi.org/10.1016/j.chbr.2023.10034

Sahi, A. M., Khalid, H., Abbas, A. F., Zedan, K., Khatib, S. F. A., & Al Amosh, H. (2022). The Research Trend of Security and Privacy in Digital Payment. Informatics, 9(2), 32. https://doi.org/10.3390/informatics9020032

Schäfer, F., Gebauer, H., Gröger, C., Gassmann, O., & Wortmann, F. (2023). Data-driven business and data privacy: Challenges and measures for product-based companies. Business Horizons, 66(4), 493–504. https://doi.org/10.1016/j.bushor.2022.10.002

Schweidel, D. A., Bart, Y., Inman, J. J., Stephen, A. T., Libai, B., Andrews, M., Rosario, A. B., Chae, I., Chen, Z., Kupor, D., Longoni, C., & Thomaz, F. (2022). How consumer digital signals are reshaping the customer journey. Journal of the Academy of Marketing Science, 50(6), 1257–1276. https://doi.org/10.1007/s11747-022-00839-w

Seethamraju, Ravi Diatha, & Krishna Sundar. (2019). Digitalization of Small Retail Stores - Challenges in Digital Payments. Proceedings of the 52nd Hawaii International Conference on System Sciences. DOI:10.24251/HICSS.2019.621

Siona Listokin. (2015). Industry Self-Regulation of Consumer Data Privacy and Security. John Marshall Journal of Information Technology & Privacy Law, 32(1). https://repository.law.uic.edu/jitpl/vol32/iss1/2/

Tanai Khiaonarong, & Terry Goh. (2020). Fintech and Payments Regulation: Analytical Framework. https://www.imf.org/en/Publications/WP/Issues/2020/05/29/Fintech-and-Payments-Regulation-Analytical-Framework-49086

TIMOTHY WOLTERS. (2000). “Carry Your Credit in Your Pocket”: The Early History of the Credit Card at Bank of America and Chase Manhattan. Enterprise & Society, 1(2), 315–354. https://doi.org/10.5089/9781513531496.001

Velez, G. (2025). A systematic review of mobile banking, fintech innovations, and regulatory gaps to achieve financial inclusion in the Philippines. Journal of Interdisciplinary Perspectives, 3(3), 390–397. https://doi.org/10.69569/jip.2025.056

Victor Murinde, Efthymios Rizopoulos, & Markos Zachariadis. (2022). The impact of the FinTech revolution on the future of banking: Opportunities and risks. International Review of Financial Analysis, 81. https://doi.org/10.1016/j.irfa.2022.102103

Wisniewski, P. J., & Page, X. (2022). Privacy Theories and Frameworks. In Modern Socio-Technical Perspectives on Privacy (pp. 15–41). Springer International Publishing. https://doi.org/10.1007/978-3-030-82786-1_2

Zaki Irfan Al Hafizh, & Anas Hidayat. (2022). The role of digital payment benefits toward switching consumer behavior in the case of OVO application. International Journal of Research in Business and Social Science, 11(7), 23–34. DOI: 10.20525/ijrbs.v11i7.2156

Zhang, W., Siyal, S., Riaz, S., Ahmad, R., Hilmi, M. F., & Li, Z. (2023). Data Security, Customer Trust and Intention for Adoption of Fintech Services: An Empirical Analysis from Commercial Bank Users in Pakistan. SAGE Open, 13(3). https://doi.org/10.1177/21582440231181388

Zhimao Wang, & Xucheng Huang. (2023). Understanding the role of digital finance in facilitating consumer online purchases: An empirical investigation. Finance Research Letters, 55(Part B). https://doi.org/10.1016/j.frl.2023.103939

Zlatko Bezhovski. (2016). The Future of the Mobile Payment as Electronic Payment System. European Journal of Business and Management, 8(8). https://core.ac.uk/download/pdf/234627158.pdf

Downloads

Published

2025-09-29

How to Cite

AllahRakha, N., Xamdamovna, T. G., Sokhibjonovich, B. S., Narziev, O., & Temurbek, P. (2025). Privacy and Security Risks in Cross-Border Digital Payment Systems . Legality : Jurnal Ilmiah Hukum, 33(2), 553–584. https://doi.org/10.22219/ljih.v33i2.40400

Issue

Section

Journal's Articles