The development of financial technology (fintech), especially online lending services (pinjol), has provided easy financial access for the public. However, on the other hand, serious problems have emerged related to the misuse and illegal distribution of customer personal data by pinjol service providers. This study aims to analyze the legal responsibilities that can be imposed on pinjol organizers for customer data leaks and to evaluate the influence of Law Number 27 of 2022 concerning Personal Data Protection (UU PDP) in providing legal protection for victims. The research method used is normative juridical with a statutory, conceptual, and case study approach. Data were obtained through literature reviews, laws and regulations, and court decisions. The results of the study show that pinjol organizers who illegally distribute customer data can be subject to criminal, civil, and administrative legal responsibilities. Law Number 27 of 2022 concerning Personal Data Protection provides a fairly strong legal basis, but there are still obstacles in its implementation, such as the suboptimal supervision mechanism and weak sanctions against perpetrators. The conclusion of this study is the need to strengthen the derivative regulations of Law Number 27 of 2022 concerning Personal Data Protection and increase the active role of supervisory authorities such as the OJK and Kominfo in supervising data processing practices by online loan providers. It is recommended that the government immediately draft technical implementing regulations and expand socialization regarding data subject rights to the public.