The rapid advancement of digital technology has placed the government in the position of a large-scale personal data controller through various E-Government platforms and public service applications. However, the government's capacity to protect this data has proven inadequate, as demonstrated by several major data breach incidents involving national platforms such as the Temporary National Data Center (PDNS) in 2024, Satu Sehat, and DPMPTSP Online. This research aims to analyze the civil liability of government agencies as personal data controllers in cases of personal data breaches, viewed through the framework of Law Number 27 of 2022 on Personal Data Protection (UU PDP) and Law Number 30 of 2014 on Government Administration (UU AP). The research method employed is normative juridical (doctrinal legal research) through a statutory approach and a conceptual approach, with primary legal materials drawn from the aforementioned laws and secondary materials from scientific articles and relevant legal textbooks. The findings indicate that the government, as a public body and personal data controller under UU PDP, can be held civilly liable when a data breach occurs due to negligence or unlawful acts in data management. Civil liability may arise through two mechanisms: the unlawful act (onrechtmatige overheidsdaad) mechanism under Article 1365 of the Civil Code, and the administrative court (PTUN) mechanism under UU AP. However, implementation faces significant obstacles, including the absence of government implementing regulations for UU PDP, fragmentation of supervisory authority, the absence of standardized compensation mechanisms, and limited institutional capacity. This research concludes that comprehensive regulatory harmonization, the establishment of a strong Personal Data Protection Authority, and the development of fast, accessible compensation procedures are urgently needed to realize effective legal protection for citizens' personal data.