EnglishID
Indonesia flag

Indonesia

Indonesia Data Privacy Laws: Complete UU PDP Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202620 min read
Indonesia Data Privacy Laws: Complete UU PDP Compliance Guide (2026)

Frequently Asked Questions

Is Indonesia's PDP Law currently in force and enforceable?

Yes. Law No. 27 of 2022 on Personal Data Protection (UU PDP) was signed on October 17, 2022, with a two-year transition period that expired on October 17, 2024. The law is fully in force. However, implementing Government Regulations and the dedicated supervisory agency (Lembaga PDP) have not yet been formally established as of May 2026. The Ministry of Communication and Digital Affairs (Komdigi) handles interim enforcement through its Directorate General of Digital Space Supervision under MOCD Regulation 1/2025.

Has a dedicated data protection authority been established in Indonesia?

Not yet as of May 2026. The UU PDP (Art. 58) mandates the President to establish a Personal Data Protection Agency (Lembaga PDP). A draft Presidential Regulation governing the agency's structure entered the harmonization stage at the Ministry of Law in October 2025. The government has stated a target of 2026 for the agency to become operational, but the timeline has shifted previously. Until the Lembaga PDP launches, Komdigi's Directorate General of Digital Space Supervision exercises supervisory functions.

What are the maximum penalties for violating Indonesia's PDP Law?

Administrative fines reach up to 2% of annual revenue. Criminal penalties for individuals include up to 6 years imprisonment and fines of up to IDR 6 billion (approx. USD 368,000) for creating false personal data, and up to 5 years for unlawful collection or use. For corporate entities, fines can reach IDR 60 billion (approx. USD 3.68 million), and additional sanctions include license revocation, business suspension, asset confiscation, and dissolution.

Does the UU PDP apply to foreign companies outside Indonesia?

Yes. The UU PDP has extraterritorial reach. It applies to any organization that processes personal data of Indonesian data subjects or conducts processing activities that produce legal effects within Indonesian territory. Foreign companies serving Indonesian customers, processing Indonesian employee data, or targeting the Indonesian market must comply regardless of where their servers or corporate entities are located.

How does Indonesia's PDP Law handle cross-border data transfers?

Article 56 of the UU PDP establishes a three-tier framework. Transfers are permitted where the receiving country provides equivalent or higher protection (adequacy), or where binding safeguards such as standard contractual clauses ensure adequate protection, or where the data subject provides explicit informed consent. The law does not impose general data localization requirements. A Government Regulation providing detailed adequacy and safeguard guidance has been submitted to the President but had not been signed as of May 2026.

When must a DPO be appointed under the UU PDP?

Article 53 requires a DPO when any one of three conditions is met: processing is for a public interest purpose; core activities involve regular and systematic large-scale monitoring of data subjects; or core activities involve large-scale processing of specific (sensitive) personal data. The Indonesian Constitutional Court confirmed that meeting a single condition is sufficient. Organizations processing health, biometric, financial, or children's data at scale, or conducting systematic user profiling, should assess whether they meet the threshold.

What is the breach notification deadline under the UU PDP?

Article 46 requires controllers to notify affected data subjects and the supervisory authority within 3x24 hours (72 hours) of becoming aware of a personal data breach. The notification must describe the data compromised, when and how the breach occurred, and what remedial steps have been taken. Where a breach disrupts public services or significantly affects the public interest, a public notification is also required.

Does the UU PDP supersede the older Kominfo Regulation 20/2016?

The UU PDP is the primary and superior instrument. Article 75 of the UU PDP confirms that existing laws and regulations on personal data remain valid only to the extent they do not contradict the UU PDP. Kominfo Reg 20/2016 continues to apply as a supplementary instrument for electronic systems where its provisions are consistent with the UU PDP. Where they conflict, the UU PDP prevails. The UU PDP also extended coverage beyond electronic systems to all personal data processing, digital and physical.

Are there data localization requirements under Indonesian law?

The UU PDP does not impose a general data localization requirement. However, Government Regulation No. 71 of 2019 on Electronic Systems and Transactions (GR 71/2019) continues to require local storage for certain categories of strategic data managed by public electronic system operators. Organizations operating electronic systems in Indonesia must assess obligations under both the UU PDP and GR 71/2019 in parallel, as they address related but distinct aspects of data governance.

What is the status of implementing regulations for the UU PDP?

As of May 2026, none of the nine implementing Government Regulations mandated by the UU PDP have been enacted. A consolidated draft RPP PDP was submitted to the President and reportedly reached its final stage, but presidential signature had not occurred by the time of this review. Until enacted, certain provisions of the UU PDP lack the granular procedural detail originally envisaged. Controllers should monitor the Indonesian State Gazette and jdih.komdigi.go.id for publication.

Updates

Verification pass: confirmed the transition-period-ended and Komdigi-naming facts already reflected the current status (no reversal needed). Added a primary-source citation to Komdigi's JDIH implementing-regulation status page and a citation to hukumonline reporting on the Badan PDP Presidential Regulation's Ministry of Law harmonization stage. Added internal links to the data localization, DPO requirements, standard contractual clauses, and [GDPR](/world-laws/world-data-privacy-laws) comparison pages.

Expanded to 6,200 words. Updated supervisory authority section to reflect MOCD Regulation 1/2025 interim arrangement and PDP Agency harmonization-stage status. Added implementing regulation status detail, ITE Law / Kominfo Reg 20/2016 legacy framework section, 2024-2025 enforcement incidents, GDPR comparison table, and expanded FAQ.

Initial publication. Covered UU PDP structure, legal bases, data subject rights, DPO requirements, breach notification, cross-border transfers, and penalties.

Sources and References

  1. Law No. 27 of 2022 on Personal Data Protection (UU PDP) — Official Text, Peraturan.go.id(peraturan.go.id).gov
  2. UU No. 27 Tahun 2022 — JDIH BPK RI(peraturan.bpk.go.id).gov
  3. Undang-Undang Nomor 27 Tahun 2022 — JDIH Komdigi(jdih.komdigi.go.id).gov
  4. Indonesia: Personal Data Protection Act Enters into Force — Library of Congress(loc.gov).gov
  5. Law No. 11 of 2008 on Electronic Information and Transactions (UU ITE) — JDIH Komdigi(jdih.komdigi.go.id).gov
  6. Data Protection Laws and Regulations Report 2025-2026: Indonesia — ICLG(iclg.com)
  7. Data Protection and Privacy 2026: Indonesia Trends and Developments — Chambers and Partners(practiceguides.chambers.com)
  8. Update on Implementing Regulation for Indonesia PDP Law — Makarim and Taira S.(makarim.com)
  9. Indonesia PDP Law Update: DPO Mandate Confirmed — Assegaf Hamzah and Partners(ahp.id)
  10. Highlights of Indonesia Personal Data Protection Law — Norton Rose Fulbright(nortonrosefulbright.com)
  11. Indonesia PDP Bill Overview — Future of Privacy Forum(fpf.org)
  12. Breach Notification in Indonesia — DLA Piper(dlapiperdataprotection.com)
  13. Transfer of Personal Data in Indonesia — DLA Piper(dlapiperdataprotection.com)
  14. Indonesia Personal Data and Cybersecurity Quarterly Update October 2025 — HBT Law(hbtlaw.com)
  15. Consequences of Breaches of Data Protection Law in Indonesia — SSEK Law Firm(ssek.com)
  16. Indonesia PDP Law Cross-Border Transfer Requirements — Makarim and Taira S.(makarim.com)
  17. Indonesia Investigates 58 Million Student Data Breach — Tempo English(en.tempo.co)
  18. Digital Oversight in Indonesia: Personal Data Protection Faces Rising Risks — Batam News Asia(batamnewsasia.com)
  19. Indonesia Data Protection and Privacy Laws 2026 Guide — SSEK Law Firm(ssek.com)
  20. UU PDP (Law No. 27/2022) implementing-regulation status -- Komdigi JDIH legal database(jdih.komdigi.go.id).gov
  21. Menanti Disahkannya Aturan Turunan UU PDP (RPP harmonization status report)(hukumonline.com)
Share: