The rapid expansion of e-commerce in Indonesia has transformed consumer transactions while creating increasingly complex legal risks concerning data security and customer privacy. This study analyzes the legal challenges faced by e-commerce businesses in protecting personal data, maintaining the confidentiality and integrity of digital information, and ensuring accountability when data breaches or misuse occur. A normative juridical method is employed through an examination of statutory regulations, legal principles, and relevant literature, particularly the Personal Data Protection Law, the Electronic Information and Transactions Law, and regulations governing electronic systems and consumer protection. The analysis focuses on platform compliance, consent and transparency, third-party data processing, cybersecurity governance, cross-border data transfers, consumer complaint mechanisms, and the use of artificial intelligence and behavioral profiling. The findings indicate that Indonesia has developed a relatively comprehensive legal framework, but its implementation remains constrained by uneven business compliance, limited supervisory capacity, overlapping sectoral rules, inadequate incident reporting, and low consumer digital literacy. Small and medium-sized digital businesses also face difficulties in translating legal obligations into practical security procedures. Effective protection therefore requires harmonized regulations, stronger institutional supervision, clear allocation of responsibility among platform operators and business partners, privacy-by-design practices, regular security audits, and accessible dispute-resolution mechanisms. These measures are essential to strengthen consumer trust and support a secure, fair, and sustainable e-commerce ecosystem.