Technology-based peer-to-peer lending services provide rapid access to financing while requiring extensive personal-data processing. A recurring legal problem arises when a borrower lists a third party’s phone number as an emergency contact without the data owner’s consent and the number is subsequently used in collection activities. This normative legal research employs statutory and conceptual approaches to examine the legal status of the third party, the duties of a licensed lending service provider, and the allocation of administrative, civil, and criminal liability. The study finds that a third-party phone owner is a personal-data subject and does not become a debtor or guarantor merely because the number is listed. Under Financial Services Authority Circular Letter No. 19/SEOJK.06/2025, a provider must confirm and obtain the emergency contact owner’s consent, explain the submitted data and associated risks, document the confirmation and consent, and may use the contact only to confirm the borrower’s whereabouts rather than to collect the debt. Preventive protection therefore rests on verification, purpose limitation, documentation, and supervision, while repressive protection includes cessation or deletion requests, regulatory complaints, compensation claims, and sanctions. Liability must be attributed to each actor and is not automatic: administrative sanctions concern licensed providers, civil liability requires proof of an unlawful act, fault, loss, and causation, and criminal liability arises only when the statutory elements and culpability are proven.