The rapid development of Buy Now, Pay Later (BNPL) services in Indonesia, particularly GoPayLater managed by PT Multifinance Anak Bangsa (MAB), has increased the risk of account hacking, resulting in financial losses for users. This study aims to analyze the legal liability of the GoPayLater service provider for consumer losses caused by account hacking. The background of this research lies in the inadequate implementation of data management supervision by the GoPayLater provider, which has adversely affected service users. The research problem addressed is the form of legal liability borne by the GoPayLater service provider when account hacking causes losses to users. The objective of this study is to examine the liability of the GoPayLater provider and evaluate personal data protection policies within the context of digital financial transactions. This research employs a normative legal research method using statutory, conceptual, and personal data protection approaches. The findings indicate that the GoPayLater service provider may be held civilly, criminally, or administratively liable if negligence in managing consumers' personal data is proven. Although the Financial Services Authority has established regulations and conducts supervision, gaps remain in their implementation and in inter-agency coordination.
Copyrights © 2026