The business licensing reform enacted through Law Number 11 of 2020 concerning Job Creation has given rise to the Risk-Based Online Single Submission (OSS RBA) system, which relies on real-time data interoperability from various government agencies. The ratification of Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) introduces a new legal regime that creates ambiguity regarding the legal status of the parties within the OSS RBA ecosystem. This research aims to analyze the legal qualification of the parties involved in personal data processing within the ecosystem, evaluate the application of the Joint Controllership concept in OSS RBA interoperability, and formulate a mechanism for allocating legal responsibility in the event of personal data protection failures. The research employs a normative juridical method with statutory and conceptual approaches. The result indicate that the relationship between the Ministry of Investment/BKPM and the data source agencies is more appropriately qualified as Joint Controllers, as they collectively determine the purposes and means of personal data processing. A legal void exists in the regulation of joint controllership within the OSS RBA. The absence of agreements or derivative technical regulations governing the allocation of responsibility creates ambiguity that can be detrimental to data subjects. Therefore, derivative regulations are necessary to stipulate in detail the joint controllership mechanism and to mandate the preparation of Data Sharing Agreements (DSAs) between agencies, which would define the responsibilities of each party in accordance with the provisions of the PDP Law.