Muhammad Ivan Arta Maulana; Ni Putu Rai Yuliartini; Dewa Gede Sudika Mangku
The rapid growth of the e-commerce sector in Indonesia has significantly increased the use of personal data in digital transactions, which in turn has led to more complex risks of data breaches. This issue reflects a gap between technological advancement and the readiness of adequate data protection systems. This study aims to analyze the implementation of Law Number 27 of 2022 on Personal Data Protection in addressing data breaches on e-commerce platforms and to identify factors influencing its effectiveness. The research employs a normative legal method with a statutory and literature approach. The findings indicate that although the regulation provides a strong legal foundation, its implementation still faces several challenges, including weak supervision, low compliance among business actors, and limited public awareness in protecting personal data. In addition, technical vulnerabilities and human error are identified as the primary causes of data breaches. The implications of this study highlight the importance of strengthening supervision, improving data security standards by e-commerce platforms, and enhancing public education to establish a more effective and sustainable personal data protection system in Indonesia.