This study examines how criminal and civil law protect businesses engaged in digital transactions from cybercrime, with a comparative focus on Indonesia and the European Union. The research adopts a normative juridical and comparative approach, analyzing statutory regulations, regulatory instruments, and scholarly literature on cyberlaw, cybersecurity, and data protection. In Indonesia, legal protection is still dominated by a punitive criminal law orientation through the ITE Law and related provisions, while civil remedies for business losses caused by cyber incidents remain fragmented and largely dependent on general tort and contract principles, leading to legal uncertainty for businesses. In contrast, the European Union has developed a more integrated framework through the GDPR, NIS2 Directive, and Digital Services Act, which combine criminal, civil, and administrative mechanisms, including strict compliance duties, data breach notification, joint and several liability, and strong supervisory structures. The findings show that the EU model embeds cybersecurity and data protection into corporate governance and risk management, whereas Indonesia is still in a transitional phase toward a more coherent system. The study concludes that Indonesia can strengthen legal protection for businesses by reinforcing civil and administrative liability, clarifying multi‑party responsibility in digital ecosystems, adopting risk‑based and governance‑oriented regulatory principles, and improving institutional coordination in the enforcement of cyberlaw and cybersecurity regulations.
Copyrights © 2026