The enactment of Law Number 27 of 2022 on Personal Data Protection (PDP Law) marks a new chapter in data governance in Indonesia, particularly within the rapidly expanding electronic commerce ecosystem. This study aims to analyze the legal framework for the protection of consumers' personal data in e-commerce transactions following the enforcement of the PDP Law, as well as to identify normative gaps that may undermine the effectiveness of such protection. This research employs a normative legal research method with a statute approach and a conceptual approach, utilizing primary legal materials in the form of relevant legislation and secondary legal materials comprising scholarly literature, legal doctrine, and pertinent judicial decisions. The findings reveal that the PDP Law has established a more comprehensive legal foundation than its predecessor regulations, particularly through the codification of the consent principle, data subject rights, and obligations incumbent upon data controllers; nevertheless, several normative disharmonies were identified between the PDP Law and Law Number 11 of 2008 as amended by Law Number 19 of 2016 on Electronic Information and Transactions, as well as Law Number 8 of 1999 on Consumer Protection, with the absence of a functionally operational independent supervisory body during the transitional period constituting a structural impediment to legal enforcement. This study concludes that cross-sectoral regulatory harmonization and the establishment of an effective data protection authority are indispensable prerequisites for the substantive realization of consumer personal data protection in Indonesia's e-commerce transactions.