The advancement of digital technology within the banking sector has introduced significant challenges in safeguarding customers’ personal data. This article aims to analyze the legal protections available to bank customers affected by personal data breaches, based on the provisions of Law Number 27 of 2022 concerning Personal Data Protection. This research employs a normative legal method through literature review and statutory analysis. The findings indicate that the law establishes fundamental data protection principles, recognizes the rights of data subjects, and outlines sanctions for violations. However, the implementation of these provisions within financial services continues to encounter challenges in integrating with sectoral banking regulations. Enhanced coordination between regulatory authorities is essential to establish a legal protection system that is both effective and responsive amid ongoing digitalization. Keywords: Customer, Data Breach, Legal Protection, Personal Data, PDP Law