The digital era has brought with it the high rate of information exchange through Electronic System Providers (ESPs). Despite this convenience, however, there is a serious threat of user personal data leaks. This article examines the forms of legal liability, both criminal and civil, that can be imposed on ESPs when they fail to protect user data. Using normative juridical research methods, this study finds that under civil law, injured users can file a lawsuit for damages based on an Unlawful Act (PMH). Criminally, with the enactment of Law Number 27 of 2022 concerning Personal Data Protection (UU PDP), ESPs can be subject not only to administrative sanctions but also to criminal sanctions targeting corporations and their managers if there is evidence of intent or gross negligence.
Copyrights © 2026