The practice of reusing (recycling) expired mobile phone numbers is an administrative necessity for the sake of limited numbering efficiency. However, in the digital ecosystem, this phenomenon poses a residual data risk that threatens constitutional privacy rights because new numbers are often still linked to the old owner's bank accounts and social media. This study aims to analyze the legal construction of phone number reuse from the perspective of personal data protection and to formulate the form of legal accountability of telecom providers for the damages caused. The research used a normative juridical method with a statute approach, a conceptual approach, and a comparative approach. The study found a conflict between Minister of Communication and Informatics Regulation No. 14 of 2018, which focuses on numbering efficiency, and Law No. 27 of 2022 on Personal Data Protection (PDP Law). Telecom operators, as Data Controllers, have a legal responsibility to apply the right to erasure before giving out phone numbers again. If they don't make sure a number is 'clean,' they can be sued in civil court for breach of contract (Article 1239 of the Civil Code) or for unlawful acts (Article 1365 Civil Code in conjunction with Article 12 of the PDP Law). This study recommends reconstructing sectoral regulations by adopting the Privacy by Design principle through providing interconnection clearing Application Programming Interface (API) infrastructure across platforms to ensure legal certainty and consumer protection.
Copyrights © 2026