The alleged leakage of customers' personal data at Bank Syariah Indonesia (BSI) resulting from the LockBit 3.0 ransomware attack in 2023 has raised serious concerns regarding the protection of personal data in the digital banking sector. This incident demonstrates that digital transformation in banking services not only enhances service efficiency but also increases the risk of personal data security breaches. This study aims to analyze the legal protection of customers' personal data at Bank Syariah Indonesia based on Law Number 27 of 2022 concerning Personal Data Protection and to examine BSI's legal liability for the alleged personal data breach. This research employs a normative legal research method using statutory and conceptual approaches. Legal materials were collected through library research, including legislation, legal textbooks, scholarly journal articles, and other relevant legal documents. The findings indicate that the protection of customers' personal data in the banking sector is regulated under the Personal Data Protection Law, the Banking Law, the Islamic Banking Law, and regulations governing the financial services sector. The alleged data breach at BSI indicates a potential failure to fulfill the obligations of a data controller in safeguarding personal data and providing notification to data subjects. BSI's accountability measures were primarily implemented through the restoration of banking services and the strengthening of cybersecurity systems. However, transparency in notifying affected customers has not yet been fully optimized.