Does Indonesia's Personal Data Protection Law (UU 27/2022) Apply to My Company? A 2026 Compliance Guide
Short answer: Yes — if your company processes the personal data of people in Indonesia, Law No. 27 of 2022 (UU PDP) almost certainly applies, even if your business is based abroad (Article 2). The two-year grace period ended on 17 October 2024, so compliance is now mandatory. Administrative fines reach 2% of annual revenue (Article 57), and criminal fines run to IDR 6 billion.
Indonesia now has a comprehensive, GDPR-style data protection statute — and most foreign companies operating in or selling into the country are still not compliant with it. The transition period is over, enforcement has begun, and the law reaches well beyond Indonesian borders. If you run a SaaS product, an e-commerce store, an app, or a PT PMA that holds employee and customer records, this is no longer a "nice to have."
This is also a topic your incorporation or visa agent will not brief you on. It sits at the intersection of technology, compliance, and real financial exposure — exactly where precise legal advice matters and generic setup checklists fall silent.
What is UU PDP, and when did it take effect?
Law No. 27 of 2022 on Personal Data Protection ("UU PDP" or the "PDP Law") was enacted on 17 October 2022. It is Indonesia's first omnibus data protection law, replacing a patchwork of sector rules with a single, GDPR-influenced framework covering consent, data subject rights, controller and processor duties, breach notification, cross-border transfers, and both administrative and criminal sanctions.
Article 74 gave organizations a two-year transition period to comply. That period expired on 17 October 2024. In other words: the grace window has closed, and the obligations below are live law today, not future planning.
Does the law apply to a company based outside Indonesia?
Often, yes. Article 2 gives the PDP Law extraterritorial reach. It applies not only to controllers and processors inside Indonesia but also to those outside Indonesia whose data processing has legal consequences within Indonesia or affects Indonesian data subjects.
Practically, that means a Singapore-incorporated app with Indonesian users, a US e-commerce platform shipping to Jakarta, or an offshore parent handling the HR data of an Indonesian subsidiary can all fall within scope — regardless of where their servers sit. If your users, customers, or employees are in Indonesia, assume the law reaches you until a lawyer tells you otherwise.
What kinds of personal data does it cover?
The PDP Law distinguishes two categories (Article 4): general personal data (name, gender, nationality, religion, and data combined to identify a person) and specific personal data — the sensitive category, including health data, biometric data, genetic data, criminal records, children's data, and financial data. Specific personal data attracts heightened obligations, so mapping which category you hold is the first compliance step.
What must my company actually do to comply?
The core obligations track international norms but with Indonesian specifics:
- Establish a lawful basis for every processing activity. Article 20 recognizes six lawful bases, including consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public duty, and legitimate interests. Where you rely on consent, it must be explicit, informed, and — importantly — provided in the Indonesian language (a bilingual format is acceptable). This mirrors the dual-language rule that already trips up foreign companies on their commercial contracts; see our guide on Indonesia's Indonesian-language requirement for contracts.
- Honor data subject rights. Articles 5–13 give individuals rights to be informed, to access, to rectify, to erase, to withdraw consent, to object to solely automated decision-making and profiling, and to data portability. You need internal processes to receive and act on these requests.
- Notify breaches within 72 hours. Under Article 46, when a controller becomes aware of a personal data breach it must notify both the affected data subjects and the supervisory authority within 3×24 hours (72 hours), describing the data involved, how and when the breach occurred, and the mitigation steps taken. Where the breach affects the public interest, a public notice may also be required.
- Control cross-border transfers. Article 56 permits sending personal data outside Indonesia only if the destination country offers a level of protection equal to or higher than the PDP Law; failing that, you must put adequate and binding safeguards in place; and failing that, you must obtain the data subject's consent.
- Appoint a Data Protection Officer where required (see below).
Does my company need a Data Protection Officer — and did that just change?
This is where recency matters, and where most published guidance is now out of date.
Article 53(1) requires a controller or processor to appoint a Data Protection Officer (DPO) in three situations: (1) processing for public services; (2) core activities that require regular and systematic monitoring of personal data on a large scale; or (3) core activities involving large-scale processing of specific/sensitive data or crime-related data.
Originally, these three conditions were read cumulatively — you needed all three before the obligation bit. That changed. In Constitutional Court Decision No. 151/PUU-XXII/2024, issued on 30 July 2025, the Court reinterpreted Article 53(1) so that satisfying any one of the three conditions now triggers the obligation to appoint a DPO. The practical effect is significant: the pool of companies that must appoint a DPO has widened sharply, and it is no longer confined to government bodies or large corporations. If your core business involves large-scale monitoring or sensitive-data processing, you likely need a DPO now.
What happens if we don't comply?
Two tracks of exposure — administrative and criminal — sit side by side.
| Exposure | Basis | What it looks like |
|---|---|---|
| Administrative sanctions | Article 57 | Written warning; temporary suspension of processing; deletion/destruction of personal data; administrative fine up to 2% of annual revenue |
| Criminal — unlawful collection/use | Article 67 | Up to 5 years imprisonment and/or IDR 5 billion fine (unlawful disclosure: up to 4 years / IDR 4 billion) |
| Criminal — falsifying data | Article 68 | Up to 6 years imprisonment and/or IDR 6 billion fine, plus possible asset confiscation |
| Corporate offenders | Arts 67–70 | Where the offender is a corporation, criminal liability is imposed as fines only (at a multiplied maximum), alongside possible additional penalties |
For a company with meaningful Indonesian revenue, the 2%-of-revenue administrative fine alone can dwarf the cost of getting compliant in the first place.
Who is enforcing this right now?
Here is the nuance that changes your risk calculus. The PDP Law directs the President to establish a dedicated data protection supervisory agency (the Lembaga PDP), and it contemplates an implementing Government Regulation (RPP PDP) to operationalize much of the detail. As of mid-2026, neither has been finalized — the implementing regulation has reportedly reached the President's desk but has not been signed, and the dedicated agency is still being set up.
In the meantime, enforcement is being handled on an interim basis by the Ministry of Communication and Digital Affairs (Komdigi), through its Directorate General of Digital Space Supervision, which has already been reviewing hundreds of digital platforms for compliance gaps. So "there's no regulator yet" is the wrong conclusion. The obligations are in force, someone is enforcing them, and the dedicated agency — likely with sharper teeth — is coming.
What this means for you
- Assume you are in scope. If you touch Indonesian users', customers', or employees' data — even from abroad — the default assumption should be that UU PDP applies (Article 2).
- The clock already ran out. The 17 October 2024 deadline is behind us; you are in the enforcement era, not the preparation era.
- Re-run your DPO analysis under the 2025 ruling. The Constitutional Court's July 2025 decision means many companies that concluded "we don't need a DPO" reached that answer under a test the Court has since discarded.
- Fix consent and cross-border flows first. Indonesian-language consent (Article 20) and compliant international transfers (Article 56) are two of the most common — and most fixable — gaps.
- Budget for the downside. A 2%-of-revenue fine (Article 57) plus criminal exposure for individuals is a board-level risk, not an IT footnote.
Common mistakes we see foreign companies make
- Assuming "we're not in Indonesia, so it doesn't apply." Article 2's extraterritorial scope defeats this assumption for most consumer-facing and employer scenarios.
- Relying on English-only consent forms. Consent that is not available in Indonesian is legally fragile under Article 20 — the same language trap that undermines contracts here.
- Treating the missing implementing regulation as a free pass. The core statutory obligations and sanctions are already in force and being enforced by Komdigi; waiting for the RPP is a bet against a live regulator.
- Skipping the DPO analysis, or using a stale one. After Decision No. 151/PUU-XXII/2024, the DPO trigger is far broader than the original cumulative reading.
- Copy-pasting a GDPR program without localizing. UU PDP is GDPR-influenced but not identical — the 72-hour breach clock, the Indonesian-language consent rule, and the specific sanction structure all need Indonesian tailoring.
Key takeaways
- UU PDP is Law No. 27 of 2022, enacted 17 October 2022; the two-year transition ended 17 October 2024 (Article 74) — compliance is mandatory now.
- The law applies extraterritorially (Article 2) to foreign companies processing Indonesian data.
- Core duties: lawful basis and Indonesian-language consent (Article 20), data subject rights (Articles 5–13), 72-hour breach notification (Article 46), and controlled cross-border transfers (Article 56).
- A DPO is required if you meet any one of three conditions (Article 53(1)), following Constitutional Court Decision No. 151/PUU-XXII/2024 (30 July 2025).
- Penalties: administrative fines up to 2% of annual revenue (Article 57) and criminal fines up to IDR 6 billion (Articles 67–68).
- No dedicated agency or implementing regulation is finalized yet (mid-2026); Komdigi enforces in the interim.
Frequently asked questions
Does Indonesia's PDP Law apply to companies based outside Indonesia? Yes, in many cases. Article 2 gives UU PDP extraterritorial effect: it applies to controllers and processors outside Indonesia where their processing has legal consequences in Indonesia or affects Indonesian data subjects. A foreign app, e-commerce seller, or parent company handling Indonesian users' or employees' data can be in scope regardless of where it is incorporated.
When did Indonesia's Personal Data Protection Law come into force? The law (No. 27 of 2022) was enacted on 17 October 2022 and gave a two-year transition period under Article 74. That period ended on 17 October 2024, so the law's obligations — consent, data subject rights, breach notification, and sanctions — are fully in effect and enforceable today.
What are the penalties for violating UU PDP? Administrative sanctions under Article 57 include written warnings, suspension of processing, data deletion, and fines of up to 2% of annual revenue. Criminal provisions in Articles 67 and 68 carry up to 5–6 years' imprisonment and fines up to IDR 6 billion; where the offender is a corporation, the penalty is imposed as fines only.
Does my company need to appoint a Data Protection Officer? Possibly. Article 53(1) requires a DPO for processing tied to public services, large-scale regular and systematic monitoring, or large-scale processing of sensitive or crime-related data. Following Constitutional Court Decision No. 151/PUU-XXII/2024 (30 July 2025), meeting any one of these conditions — not all three — now triggers the obligation, greatly widening who must appoint a DPO.
Can I transfer Indonesian personal data overseas? Yes, but conditionally. Article 56 allows cross-border transfer only if the destination jurisdiction provides protection equal to or higher than the PDP Law; if not, you must implement adequate and binding safeguards; and if neither is available, you must obtain the data subject's consent. Documenting which route you rely on is essential.
This article is general information current as of August 2026, not legal advice. Indonesian data protection regulations are still developing — the implementing Government Regulation and dedicated supervisory agency are not yet finalized — and the law applies differently to each situation. Confirm your specific position with a licensed advisor before acting — we're happy to help.
Share this article
