The implementation of the Coretax System represents a major step in the digital transformation of Indonesia’s tax administration by integrating taxpayer data into a centralized electronic system. However, this modernization raises legal issues concerning personal data protection, electronic information security, and the harmonization of tax and digital governance regulations. This study aims to analyze the legal status of the Directorate General of Taxes (DGT) as a personal data controller and electronic system operator, evaluate its legal responsibility in cases of system failure or data breaches, and examine the harmonization between the General Provisions and Tax Procedures Law (KUP Law), the Personal Data Protection Law (PDP Law), and the Electronic Information and Transactions Law (ITE Law). This research employs a normative juridical method using statutory and conceptual approaches with qualitative legal analysis. The findings reveal that the DGT’s dual legal position creates overlapping obligations and legal uncertainty due to the absence of clear technical regulations on data protection, electronic system security, and inter-agency accountability. This study concludes that harmonized regulations and comprehensive technical standards are essential to ensure legal certainty, strengthen personal data protection, and support accountable digital tax administration in Indonesia.
Copyrights © 2026