LEGAL PROTECTION OF FACEBOOK USERS’ PERSONAL DATA IN INDONESIA UNDER THE PERSONAL DATA PROTECTION LAW
Abstract
The rapid advancement of digital technology has enabled seamless global communication, yet it simultaneously heightens the risk of personal data breaches. A salient example is the Facebook data incidents between 2018 and 2021 which affected millions of Indonesian users and revealed systemic weaknesses in data governance. Earlier regulatory instruments, particularly the Information and Electronic Transactions Law (UU ITE), provided limited remedies and made accountability for data controllers difficult to enforce. This study examines legal protections for personal data and the legal liability of Meta through a normative juridical method integrating statutory, conceptual, and case-based analyses using descriptive secondary data. The analysis focuses on key provisions of the Personal Data Protection Law, including Article 17, which guarantees data subject rights to access, correct, and delete their data; Article 18, which obliges controllers to implement adequate security measures to prevent breaches; Article 58, which establishes supervisory authorities to ensure compliance; and Article 75, which imposes administrative sanctions as a deterrent. These provisions collectively strengthen legal certainty for victims and address deficiencies in prior regulations by compelling global digital platforms to adopt higher compliance standards. In conclusion, the Personal Data Protection Law constructs a comprehensive protection regime by affirming user rights and enforcing sanctions effectively.
Downloads
References
Aqilah, R., Waryenti, D., Susanti, P., Tanggung, :, Negara, J., & Pelindungan, M. (2024). Tanggung Jawab Negara Mengenai Pelindungan Data Pribadi Berdasarkan Undang-Undang Nomor 27 Tahun 2022 Tentang Pelindungan Data Pribadi. Jurnal Ilmiah Kutei, 23(2), 158–172. https://doi.org/10.33369/jik.v23i2.34476
Besemer, Leo. (2020). Privacy And Data Protection. Van Haren Publishing.
Dayang, S. G., Olivia Putri, S. L., & Kyara Putri, A. K. (2025). Urgensi Pembentukan Lembaga Pengawas dalam Pembaharuan Hukum Perlindungan Data Pribadi Menurut Undang-Undang PDP. Locus Journal of Academic Literature Review, 4(2), 106–113. https://doi.org/10.56128/ljoalr.v4i2.433
Intan, S., Puwa, P., Puluhulawa, F. U., & Rahim, E. I. (2023). GAGASAN IDEAL PENGATURAN PERLINDUNGAN DATA PRIBADI SEBAGAI BENTUK HAK PRIVASI DI INDONESIA. PALAR (Pakuan Law Review), 9(2), 25–37. https://doi.org/10.33751/palar.v9i2
Khansa Rusyda, N. (2025). Perlindungan Hukum erhadap Subjek Data Kebocoran Data oleh Badan Publik Menurut UU Nomor 27 Tahun 2022. Desentralisasi : Jurnal Hukum, Kebijakan Publik, dan Pemerintahan, 2(3), 247–262. https://doi.org/10.62383/desentralisasi.v2i3.940
Lidya, S., Widayati, S. H., Novianti, M. H., Trias, M. H., Kurnianingrum, P., Luthvi, M. H., Nola, F., Kn, M., & Nadapdap, B. (2020). POLITIK HUKUM PELINDUNGAN DATA PRIBADI (B. Nadapdap, Ed.). Yayasan Pustaka Obor Indonesia. http://www.obor.or.id
Mahameru, D. E., Nurhalizah, A., Wildan, A., Haikal Badjeber, M., & Rahmadia, M. H. (2023). IMPLEMENTASI UU PERLINDUNGAN DATA PRIBADI TERHADAP KEAMANAN INFORMASI IDENTITAS DI INDONESIA. Jurnal Esensi Hukum, 5(2), 115–131. https://journal.upnvj.ac.id/index.php/esensihukum/index
Maharani, R., & Prakoso, A. L. (2024). Perlindungan Data Pribadi Konsumen Oleh Penyelenggara Sistem Elektronik Dalam Transaksi Digital. Jurnal USM Law Review, 7(1), 333–347. https://doi.org/10.58812/jhhws.v2i05.354
Mahendra, G. S. (2024). Perlindungan Hukum Terhadap Korban Yang Data Pribadi Passportnya Tersebar Akibat Kelalaian Pemerintah. Terang : Jurnal Kajian Ilmu Sosial, Politik dan Hukum, 1(3), 104–111. https://doi.org/10.62383/terang.v1i3.382
Matheus, J., & Gunadi, A. (2024). Pembentukan Lembaga Pengawas Perlindungan Data Pribadi Di Era Ekonomi Digital : Kajian Perbandingan Dengan KPPU. JUSTISI, 10(1), 20–35. https://doi.org/10.33506/jurnaljustisi.v10i1.2757
Novel, S., & Subiyanto, A. E. (2025). Perlindungan Hukum terhadap Data Pribadi Konsumen dalam Tindak Pidana Phishing pada Jasa Layanan E-Commerce Tokopedia. Jurnal Pendidikan Tambusai, 9(2), 27617–27626.
Quinn, Brendan. (2021). Data protection implementation guide : a legal, risk and technology framework for the GDPR. Kluwer Law International B.V.
R. Syailendra, M., & Fitzgerald, S. E. (2023). SOSIALISASI PERLINDUNGAN DATA PRIBADI BAGI MASYARAKAT KABUPATEN INDRAMAYU. Jurnal Serina Abdimas, 1(1), 157–165. https://doi.org/10.24912/jsa.v1i1.23845
Sa, R., Ahmad, dillah, Ayu Puspaningtyas, D., Nur Karim Al Ismariy, M., & korespondensi, A. (2025). PERLINDUNGAN HUKUM TERHADAP PRIVASI DATA PRIBADI DI ERA DIGITAL. In THE JURIS: Vol. IX (Issue 1). http://ejournal.stih-awanglong.ac.id/index.php/juris
Sidi, I., Wiraguna, A., Ars, M., & Barthos, M. (2025). HUKUM PRIVASI DAN PELINDUNGAN DATA PRIBADI DI INDONESIA (N. Rismawati, Ed.). WIDINA MEDIA UTAMA. www.freepik.com
Simanjuntak, P. H. (2024). Perlindungan Hukum Terhadap Data Pribadi pada Era Digital di Indonesia: Studi Undang-Undang Perlindungan Data Pribadi dan General Data Protection Regulation (GDPR). Jurnal Esensi Hukum, 6(2), 105–124. https://journal.upnvj.ac.id/index.php/esensihukum/index
Suroso, T., Gede, D., & Yustiawan, P. (2024). HAK SUBJEK DATA PRIBADI SEBAGAI BAGIAN DARI HAK ATAS PRIVASI DAN PENGATURANNYA DI INDONESIA. Jurnal Kertha Negara, 12(7), 798–812. https://databoks.katadata.co.id/datapublish/2022/09/13/indeks-keamanan-
Sutarli, A. F., & Kurniawan, S. (2023). Peranan Pemerintah Melalui Undang-Undang Perlindungan Data Pribadi dalam Menanggulangi Phising di Indonesia. Journal Of Social Science Research, 3(2), 4208–4221. https://j-innovative.org/index.php/Innovative
Tjatur, H., Irene C, D., Wardhana, B., & Riyanto, G. D. (2024). Pelindungan Data Pribadi dalam Jurnalisme dan Media (C. D. Prastuti, Ed.). Asosiasi Media Siber Indonesia. www.amsi.or.id
Wahyudi, E., & Adilah, D. (2024). Doxing in Cyberspace Based on Law No. 27 of 2022 on Personal Data Protection. Jurnal Idea Hukum, 10(2), 149–161. https://doi.org/10.20884/1.jih.2024.10.2.550
Wahyudi, E., Rifqi, D., & Huda, M. (2025). Pelindungan Hukum Atas Data Pribadi Anak dalam Sistem Elektronik: Perspektif UU No. 27 Tahun 2022 Tentang Pelindungan Data Pribadi dan Global. Policy and Law Journal (Polaw), 2(1), 1–14.
Copyright (c) 2026 Evita Rouli Silaban, Endik Wahyudi

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.















