The rapid development of the digital economy has accelerated the commercialization of personal data in Indonesia and Malaysia, raising significant concerns regarding cybersecurity and consumer protection. This study aims to analyze and compare the legal frameworks governing data commercialization in both countries, particularly Indonesia’s Personal Data Protection Law and Malaysia’s Personal Data Protection Act 2010. Using a normative juridical and comparative approach, the study examines regulations related to consent, transparency, consumer rights, and law enforcement. The findings indicate that although both countries have established legal protections for personal data, major challenges remain in implementation, supervision, and enforcement. Weak transparency, unclear consent mechanisms, limited institutional oversight, and inadequate sanctions continue to create risks of personal data misuse and privacy violations. Furthermore, the imbalance of power between corporations and consumers often limits individuals’ control over their personal information. This study concludes that stronger legal enforcement, improved transparency, enhanced consumer awareness, and collaboration between governments, corporations, and society are necessary to ensure effective consumer data protection and create a safer digital ecosystem in Indonesia and Malaysia.
Copyrights © 2026