The rapid development of digital technology has increased the importance of personal data while also creating greater risks of misuse that threaten the right to privacy. In response, Indonesia enacted Law Number 27 of 2022 concerning Personal Data Protection as the primary legal framework for safeguarding personal data. However, Article 65, which regulates criminal acts involving the unlawful acquisition, disclosure, and use of personal data, still contains ambiguities that may lead to inconsistent legal interpretation and enforcement. This study aims to analyze the formulation of criminal offenses under Article 65, focusing on the construction of criminal elements, the principle of legality, the typology of offenses, and criminal liability. The research employs a normative legal method using statutory, conceptual, and comparative approaches supported by a review of relevant legal literature. The findings indicate that Article 65 does not clearly define the element of fault, the scope of the term “unlawfully,” or the nature of the offense, thereby reducing legal certainty and the effectiveness of criminal liability for both individuals and corporations. Accordingly, revisions to Article 65 are needed to strengthen legal certainty and improve personal data protection in the digital era.
Copyrights © 2026