Civil Liability Of E-Commerce Platforms For Personal Data Breaches: Reconstructing The Chain From Statutory Duty To Consumer Compensation Under Indonesian Law
Abstract
The growth of electronic commerce has placed personal data at the centre of consumer transactions and, with it, has exposed consumers to harm when platforms fail to protect that data. This article examines the civil-law consequences of personal data breaches committed by e-commerce platforms under Indonesian law. It asks how platform duties, breach, attribution, causation, damage and compensation should be connected within a single coherent private-law analysis. The study applies normative legal research using statutory, conceptual and comparative approaches, examining Law Number 27 of 2022 on Personal Data Protection, the Indonesian Civil Code, Law Number 8 of 1999 on Consumer Protection and the electronic-system framework, with the European General Data Protection Regulation and the case law of the Court of Justice of the European Union as comparators. The article finds that Indonesian law already contains every ingredient required for a civil claim but distributes them across regimes that are not doctrinally connected, and that the compensation right in Article 12(1) of the PDP Law remains procedurally incomplete because the implementing regulation contemplated by Article 12(2) has not yet been enacted. It develops a Civil Liability Chain comprising legal duty, breach, attribution, causation, damage, civil liability and remedy, and tests that chain against the Tokopedia data-breach incident as a doctrinal illustration rather than as a retrospective application of the 2022 statute. The article argues that effective consumer redress requires an explicit causal and remedial bridge between statutory data-protection duties and Indonesian civil liability.







