Keywords:
Personal Data Protection, Cyber Security, PDP Law, Regulatory Effectiveness, Law EnforcementAbstract
The digital era has given rise to new threats to citizens' privacy rights through the leakage and misuse of personal data. In Indonesia, the enactment of Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) marked a significant milestone in the effort to create a comprehensive legal framework for personal data protection in the cyber realm. However, the implementation of the PDP Law faces various structural and technical challenges that have the potential to hinder its effectiveness. This article examines the effectiveness of personal data protection regulations in ensuring cybersecurity in Indonesia and analyzes the urgency of such regulations within the national legal system. Using normative juridical research methods enriched with sociological and comparative approaches, this article finds that the effectiveness of the PDP Law remains hampered by delays in the formulation of implementing regulations, unclear institutional arrangements for supervisory authorities, and weak cyber law enforcement capacity. Although the PDP Law has adopted international principles such as those contained in the European Union's General Data Protection Regulation (GDPR), the gap between legal norms and social reality reflected in the rise in data leak cases after its enactment demonstrates that the mere existence of regulations is insufficient without the support of adequate infrastructure, human resources, and a culture of compliance. This article recommends accelerating the formation of implementing regulations, strengthening the institutional framework of independent supervisory authorities, and increasing the capacity of cyber law enforcement as prerequisites for the effectiveness of the PDP Law.