The transformation of digital payments has prompted central banks to explore Central Bank Digital Currency (CBDC) as a new form of monetary infrastructure. However, CBDC is not merely a payment instrument; it also establishes a data processing regime, as transactions can be recorded, traced, and systematically processed. Existing studies on CBDC and privacy generally discuss design options or anonymity, but they rarely explain how personal data protection compliance should be tested before a CBDC pilot is expanded. This article addresses that gap by examining how the Digital Rupiah pilot can be designed as an ex-ante mechanism for testing compliance with Indonesia’s Personal Data Protection Law. The novelty of this article lies in its proposal of a rights-based regulatory sandbox model that integrates CBDC architecture, tiered KYC, data minimization, access governance, and remedial mechanisms into a single operational compliance framework. Using a normative legal approach and comparative method, this article interprets Indonesia’s PDP Law. It compares it with Uzbekistan’s data protection framework as an analytical mirror for assessing how processing controls and architectural requirements influence CBDC design. The article contributes to scientific knowledge by formulating a norm-to-control sandbox model that translates data protection principles into testable indicators, including purpose limitation, role-based access controls, audit trails, retention limits, and go/no-go compliance criteria. The findings show that the legitimacy of the Digital Rupiah pilot should not be measured only by technical performance or payment efficiency, but also by whether the sandbox can prove that data processing is lawful, proportionate, transparent, and auditable before wider implementation.