The digitalization of auction processes through electronic auction (e-auction) systems offers efficiency and broad reach. However, this mechanism also introduces new risks of misuse and data breaches of participants' personal data. This study aims to analyze: (1) the legal framework for protecting personal data of electronic auction participants under Indonesian positive law; (2) the alignment of current auction regulations with the principles of Law Number 27 of 2022 on Personal Data Protection (UU PDP) and (3) the forms of liability of electronic auction organizers in the event of a data breach. The method employed is normative juridical research with statute and conceptual approaches. The results indicate that sectoral auction regulations have not fully integrated UU PDP principles, particularly regarding data retention, consent clauses and privacy by design. Auction organizers, as Personal Data Controllers, may be held administratively, civilly, and criminally liable in the event of data protection failure.
Copyrights © 2026