Purpose: This study aims to analyze the legal framework for personal data protection in Indonesia following the enactment of Law No. 27 of 2022 on Personal Data Protection (PDP Law), as well as to identify the normative challenges in its implementation. Research Method: This study employs a normative legal methodology with legislative, conceptual, and comparative approaches through qualitative analysis of primary and secondary legal sources. Results and Discussion: The research findings indicate that the Personal Data Protection Act (PDP Act) has established a more comprehensive legal framework through provisions governing the rights of data subjects, the obligations of data controllers and processors, the principles of personal data processing, and mechanisms for administrative and criminal accountability. However, its implementation still requires harmonization with sector-specific regulations, strengthening supervisory institutions, refining regulations regarding AI-based data processing, profiling, and cross-border data transfers, as well as strengthening law enforcement mechanisms. Implications: These findings serve as the basis for refining policies and regulations that implement personal data protection in Indonesia. Originality: The novelty of this research lies in its doctrinal analysis, which integrates the normative framework of the Personal Data Protection Act, the harmonization of sector-specific regulations, and a comparative perspective with the GDPR.