The rapid expansion of digital technologies has significantly increased the risk of personal data misuse by corporations, creating complex legal challenges in determining corporate criminal liability. Although Indonesia enacted Law Number 27 of 2022 on Personal Data Protection, the practical application of criminal liability against corporations remains problematic due to the limitations of traditional criminal law doctrines in attributing actus reus and mens rea to corporate entities. This study aims to analyze the formulation of corporate criminal liability for the misuse of personal data and to examine future criminal law policies that can strengthen legal enforcement against corporate offenders. This research employs a normative legal method using statutory, conceptual, and comparative approaches. Primary legal materials consist of Indonesian legislation concerning personal data protection and corporate criminal liability, while secondary materials are derived from recent national and international scholarly journals. The findings demonstrate that conventional doctrines, particularly the Identification Theory, are insufficient to address decentralized digital corporations operating through automated decision-making systems. Instead, the Corporate Culture Model provides a more appropriate framework by evaluating organizational policies, governance structures, and institutional compliance in determining corporate fault. Furthermore, the study recommends integrating strict liability with a due diligence defense, strengthening digital forensic standards, recognizing AI-generated evidence, and adopting proportional turnover-based financial sanctions as effective mechanisms to enhance deterrence. These reforms are expected to establish a more adaptive and effective corporate criminal liability system capable of protecting personal data rights while ensuring legal certainty and accountability within Indonesia’s digital economy.
Copyrights © 2026