The rapid growth of digital technologies has significantly increased the collection, processing, and utilization of personal data by digital platform providers, raising concerns regarding privacy protection and data security. In response, Indonesia enacted Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) as its first comprehensive legal framework for personal data protection. This study analyzes the legal protection of digital platform users’ personal data following the enactment of the PDP Law, focusing on the legal responsibilities of digital platform providers and their alignment with the accountability principles of the European Union’s General Data Protection Regulation (GDPR). Using a qualitative library research approach, this study examines statutory regulations, scholarly literature, policy reports, and comparative legal sources. The findings indicate that the PDP Law strengthens personal data protection by recognizing data subject rights and establishing obligations for data controllers, including lawful processing, consent management, transparency, data security, breach notification, and accountability. The novelty of this study lies in its analysis of accountability-based obligations imposed on digital platform providers under the PDP Law and its evaluation of their alignment with GDPR accountability standards within the Indonesian context. The study finds that Indonesia has adopted several accountability-oriented principles similar to the GDPR, although challenges remain in regulatory enforcement, organizational compliance, cybersecurity governance, and cross-border data transfers. This study contributes to the literature by highlighting accountability as a key mechanism for enhancing legal compliance and strengthening personal data protection in Indonesia’s evolving digital ecosystem.