, Within the E-Commerce ecosystem, PayLater services depend substantially on automated credit scoring mechanisms that handle users' personal data. Although such algorithm-driven systems can render decisions instantly without human involvement, this very feature gives rise to significant legal concerns, given that the underlying data processing lacks transparency and may disregard data subjects' rights, it conversely raises serious legal issues due to its opaque data processing, which potentially neglects the rights of data subjects. This study aims to examine how Indonesian positive law regulates the personal data protection of users within such automated credit scoring systems, and to formulate the legal protection that PayLater users ought to receive. To examine these issues, this study employs a normative legal research method with statutory, conceptual, and analytical approaches. The collected primary, secondary, and tertiary legal materials are subsequently analyzed using a qualitative method. The results of the study conclude that existing regulations, particularly Law Number 27 of 2022 on Personal Data Protection and Law Number 19 of 2016 on Electronic Information and Transactions, have not specifically and comprehensively regulated the accountability of this automated credit scoring, leaving it vulnerable to violations of transparency and consent principles. Therefore, a dual-aspect legal protection model is required. Preventively, operators must obtain valid consent, implement algorithmic transparency, limit data usage, and conduct regular system audits. Repressively, injured users may pursue legal remedies through lawsuits for unlawful acts, breach of contract, or consumer rights violations under Law Number 8 of 1999 on Consumer Protection.
Copyrights © 2026