This study aims to analyze the terminological weaknesses and regulatory overlaps within the Electronic Information and Transactions Law (UU ITE) and the Personal Data Protection Law (UU PDP) that create legal loopholes for invasive direct marketing practices via SMS spam, as well as to formulate a comprehensive legal reconstruction for the privacy rights of telecommunication customers. Employing a normative legal research method with conceptual and comparative approaches, this study reveals that the ambiguous definition of personal and household activities in Article 2 paragraph (2) of the UU PDP and the multi-interpretable phrase in Article 26 paragraph (1) of the UU ITE have led to regulatory disharmony and an enforcement gap. This loophole is heavily exploited by electronic system operators and third parties to send commercial messages without prior consent, directly violating the privacy rights of the consumers. As a resolution, this study concludes and recommends legal reconstruction through regulatory synchronization adopting General Data Protection Regulation (GDPR) standards, the enforcement of product liability for telecommunication providers, the limitation of commercial promotion hours, and the implementation of strict corporate sanctions. Furthermore, the government and legislative bodies are advised to immediately establish an independent data protection supervisory agency to ensure legal certainty, justice, and utility for the public.