The rapid development of information technology has had a significant impact on the pattern of collecting, processing, and storing personal data in the digital era. However, this progress is also accompanied by an increasing threat of cybercrime, one of which is phishing attacks. Phishing is a digital fraud mode that aims to obtain personal data illegally through social engineering and manipulation of electronic systems. This study aims to analyze the form of legal protection for phishing victims in the perspective of Law Number 27 of 2022 concerning Personal Data Protection (UU PDP). Using normative legal methods and conceptual approaches, this study examines the role of state authorities such as the National Cyber and Crypto Agency (BSSN) and the Directorate of Cyber Crime (Dittipidsiber) of the National Police Criminal Investigation Unit in the procedures for handling and prosecuting phishing. The results of the study show that although the PDP Law has provided a clear legal framework, its implementation still faces challenges in technical aspects, institutional coordination, and public digital literacy. Therefore, strong synergy is needed between regulation, supervision, and public education to realize effective and sustainable personal data protection in the digital era.
Copyrights © 2025