World Watch/Indonesia/Data & Privacy

Data & Privacy · Indonesia

Data & Privacy - Indonesia

Comprehensive lawLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi / UU PDP). Interim oversight rests with the Ministry of Communication and Digital Affairs (Komdigi); a dedicated Data Protection Authority is mandated but not yet established.

Indonesia enacted a comprehensive, GDPR-inspired Personal Data Protection Law (Law No. 27 of 2022) on 17 October 2022, with a two-year transition period that ended on 17 October 2024, after which full compliance is required. The law applies to public and private controllers/processors and has extraterritorial reach. However, key institutional pieces remain incomplete: the mandated independent Data Protection Authority has not yet been formed and the detailed implementing Government Regulation is still being finalized as of early-to-mid 2026.

Comprehensive GDPR-style law in force

Law No. 27 of 2022 (UU PDP) is Indonesia's first omnibus personal-data law, modeled on the EU GDPR. It covers data subject rights, lawful processing bases (including consent), special-category data, breach notification, and cross-border transfers, applying both within and beyond Indonesia.

Transition period ended October 2024

Controllers and processors were given a two-year grace period that expired on 17 October 2024; since then full compliance is mandatory and non-compliance is enforceable.

Supervisory authority still not established

The PDP Law requires a presidentially-established Data Protection Authority (Lembaga PDP), but it has not yet been formed. A draft Presidential Regulation to create it was made public around end-February 2026 and is awaiting presidential approval, with a target launch around mid-2026.

Interim regulator is Komdigi

Pending the dedicated authority, data-protection matters are handled by the Ministry of Communication and Digital Affairs (Komdigi), specifically its Directorate General of Digital Space Supervision under Komdigi Regulation 1/2025.

Implementing regulation still pending

The detailed implementing Government Regulation (RPP PDP, reportedly ~245 articles on data-subject rights, controller obligations and oversight) completed inter-ministerial harmonization in 2025 but had not yet been formally enacted as of early 2026; it is expected to clarify cross-border transfer adequacy and safeguard mechanisms.

Key obligations and penalties

Obligations include lawful basis for processing, transparency, breach notification, appointing a DPO in defined cases, and data-protection by design. Sanctions include administrative fines up to 2% of annual revenue, suspension of processing, and criminal penalties for unlawful data acquisition or disclosure.

Machine-assisted translation · verified 5/23/2026 · orientation, not legal advice. English version →