The development of technology and the internet has changed the way humans communicate. One form of this development is the presence of social media. Social media has now facilitated fast and easy interaction. The increasing number of users also increases the potential for criminal acts of misuse of personal data. Misuse of personal data, especially on social media, requires comprehensive mitigation. This study aims to analyze efforts to overcome victims of criminal acts of misuse of personal data on social media, both through penal and non-penal channels. With a normative legal and empirical legal research approach through a study of laws and regulations and legal literature as well as interviews. This study uses a qualitative method. The results of the study show that penal efforts include collecting evidence, identifying perpetrators, and imposing sanctions in accordance with the Personal Data Protection Law. Meanwhile, non-penal efforts are carried out through public education, the establishment of personal data protection institutions, and monitoring social media activities. The main inhibiting factors in this mitigation are the lack of implementing regulations, limited technical capabilities of law enforcement officers, and minimal public awareness of the importance of personal data. This study concludes that synergy between penal and non-penal efforts is needed to protect individual privacy rights in the digital era