This study aims to analyze the legal protection of personal data subjects in the case of the 2024 data breach at the Temporary National Data Center (PDNS) managed by the Ministry of Communication and Informatics (Kominfo), based on Law Number 27 of 2022 on Personal Data Protection. The research employs a normative juridical method with a case study approach and statutory analysis. Legal materials are obtained from primary and secondary sources using literature research techniques. The findings reveal that Kominfo, as a public body and personal data controller, has not fully fulfilled its obligations to protect personal data as mandated by the law, as reflected in weak security systems, lack of transparency, and slow response to the breach incident. This study highlights the urgent need for the establishment of implementing regulations and an independent supervisory institution to ensure the effective protection of personal data for the public in Indonesia.
Copyrights © 2025