The growth of paylater services in Indonesia requires consumers to submit personal data for credit verification. However, this dependency risks triggering third-party misuse, such as identity theft, abusive collection practices, or data breaches due to weak security systems. This legal-doctrinal research analyzes types of data misuse, provider liability, and consumer protection. Utilizing statutory and conceptual approaches, the study references the Consumer Protection Act, Personal Data Protection Act, ITE Act, and OJK regulations. The results indicate that paylater providers, as data controllers, bear multi-layered legal liabilities: civil (breach of contract and tort), administrative (OJK and data authority sanctions), and potential corporate criminal liability if negligent security causes consumer losses. Legal protection includes preventive channels through transparency and informed consent, as well as repressive channels via regulatory complaints, dispute resolution, and lawsuits. This study emphasizes the importance of provider accountability in securing consumer identity data.
Copyrights © 2026