The rapid development of digital technology has significantly transformed the management, exchange, and utilization of electronic information and personal data in Indonesia. While digital transformation provides various benefits for economic, social, and administrative activities, it also creates increasing risks related to privacy violations, unauthorized access, data misuse, and cybercrime. This study aims to analyze the enforcement of Law No. 19 of 2016 concerning Amendments to Law No. 11 of 2008 on Electronic Information and Transactions in protecting electronic information and personal data in Indonesia. This research applies a normative juridical method using statutory, conceptual, and analytical approaches. The analysis is conducted through the examination of relevant legislation, legal doctrines, and academic literature concerning electronic information security and personal data protection. The findings indicate that Law No. 19 of 2016 provides an essential legal foundation for regulating electronic information, electronic transactions, and sanctions against unlawful activities in cyberspace. However, its effectiveness in protecting personal data remains limited due to the absence of comprehensive provisions regarding personal data processing, data subject rights, and institutional supervision mechanisms. The implementation of Law No. 27 of 2022 concerning Personal Data Protection strengthens Indonesia’s legal framework by providing more specific protection mechanisms, but regulatory harmonization and effective enforcement remain necessary. This study concludes that the protection of electronic information and personal data requires not only adequate legal regulations but also consistent law enforcement, institutional strengthening, technological security measures, and increased public digital awareness.
Copyrights © 2026