The expansion of Indonesia's digital economy has intensified the collection, processing, and monetization of personal data by public bodies and digital business operators. This article examines the legal responsibility of the state and digital business actors in protecting personal data under Law Number 27 of 2022 on Personal Data Protection. Using a normative juridical method with a statutory and conceptual approach, the study analyzes legislation, legal doctrine, prior research, and selected data-breach cases involving public and private digital ecosystems. The findings show that the state bears constitutional responsibility to regulate, supervise, enforce, and provide remedies for violations of personal data rights. Digital business operators, as data controllers or processors, must obtain lawful consent, secure data, notify breaches, and comply with administrative, civil, and criminal consequences. However, implementation remains constrained by incomplete implementing regulations, weak preventive supervision, and the absence of an independent personal data protection authority.
Copyrights © 2026