Indonesia’s legal paradigm shifted after Law No. 27 of 2022 on Personal Data Protection (PDP Law) was enacted to protect personal data as a constitutional right. With the enactment of this law, previously scattered sectoral regulations have been consolidated into a more structured legal system. The objective of this study is to examine how the PDPA strengthens the rights of data subjects and the obligations of data controllers; how effective information security audits using the ISO/IEC 27701 standard are in detecting system vulnerabilities; and how effective multi-stakeholder collaboration or the triple helix approach is in addressing data breaches. Qualitative descriptive analysis was used to examine the regulatory framework and its practical implementation. The study indicates that the PDP Act successfully strengthens the accountability of data controllers by establishing practical control mechanisms. Additionally, periodic security audits based on ISO/IEC 27701 have proven effective in translating legal standards into measurable technical metrics to mitigate the risks of penalties and data breaches. However, major issues such as a poorly functioning supervisory body, a public that lacks understanding of digital technology, and difficulties in coordinating sectoral regulations simultaneously remain significant obstacles to the implementation of this law. Furthermore, collaboration between the government, the IT industry, and academia has not yet been structured within a consistent framework. To ensure that Indonesia’s personal data protection ecosystem can function effectively and sustainably, it is necessary to strengthen institutional capacity and establish regular cross-sectoral coordination forums. This is despite the fact that several strategic initiatives, such as professional certification and curriculum integration, have already been launched.
Copyrights © 2026