EnglishEspañolID

Indonesia's PDP Law vs GDPR: What's Actually In Force (2026)

By Recording Law Editorial Team21 min read
Indonesia's PDP Law vs GDPR: What's Actually In Force (2026)

Frequently Asked Questions

Is Indonesia's UU PDP actually in force?

Yes, fully. The Law's two-year transition period ended October 17, 2024, and every substantive obligation, legal-basis requirements, rights, the 72-hour breach notice duty, cross-border rules, and both administrative and criminal penalties, is currently binding. What has not been established is the enforcement machinery: the independent supervisory authority (Badan PDP) has not been set up, and the implementing government regulation (PP) several provisions defer to has not been issued.

Does Indonesia have a data protection authority like the EU's DPAs?

Not yet, operationally. Pasal 58 requires an independent authority, Badan Pelindungan Data Pribadi (Badan PDP), established by the President via a Peraturan Presiden. That Perpres has not been issued; drafting received presidential initiative approval on March 4, 2025 and has been in Ministry of Law harmonization since October 2025, with Komdigi restating a 2026 completion target as of February 2026. Until it exists, Komdigi handles oversight and complaint intake on an interim basis.

Does UU PDP have a legitimate-interests lawful basis like GDPR?

Yes. Pasal 20(2)(f) provides a basis for 'other legitimate interests,' explicitly qualified by weighing purpose, necessity, and the balance of interests between the controller and the data subject, the same substantive test GDPR Article 6(1)(f) applies in practice. This is a genuine correspondence, not a gap some descriptions of Indonesian law suggest.

How does Indonesia's sensitive-data category differ from GDPR's special categories?

Pasal 4(2) treats financial data and criminal records as sensitive; GDPR's Article 9 excludes financial data entirely and handles criminal-conviction data separately under Article 10. Conversely, religion sits in Indonesia's general, non-sensitive category (Pasal 4(3)), the opposite of GDPR, where religious belief is textbook Article 9 data. Race, political opinion, union membership, and sexual orientation, all GDPR Article 9 categories, have no Pasal 4(2) counterpart at all.

What happens to cross-border data transfers without a functioning Badan PDP?

Pasal 56 sets out a four-step cascade similar to GDPR's Chapter V: an adequacy-style equivalence test, then contractual safeguards, then consent as a last resort. In practice, only the contractual-safeguard and consent steps work today, because the assessment procedure and adequacy list for the first step were assigned to the still-unissued implementing regulation.

Can someone be criminally prosecuted under Indonesia's data protection law?

Yes, and this is UU PDP's sharpest divergence from GDPR, which imposes no criminal penalties at the EU level at all. Pasal 67 and 68 criminalize unlawful, intentional acquisition, disclosure, use, or falsification of another person's data, carrying up to 4-6 years imprisonment and fines of Rp4-6 billion, plus confiscation of criminal proceeds under Pasal 69. Because prosecution runs through Indonesia's ordinary courts, it is not blocked by the still-unestablished Badan PDP.

What is the maximum penalty a company can face under UU PDP?

Two tracks run alongside each other. The administrative track (Pasal 57) caps fines at 2% of annual revenue or receipts. The criminal track (Pasal 70) can fine a corporation up to 10 times the individual maximum under Pasal 67 or 68, up to Rp50 billion or Rp60 billion, which can exceed the administrative cap for many companies. No confirmed sanction or prosecution under either track has been identified as of this review.

Does UU PDP give Indonesians a right to data portability?

Yes. Pasal 13 grants a right to obtain one's own data in a structured, machine-readable format and transmit it to another controller, closely mirroring GDPR Article 20. Indonesia also grants a right to object to fully automated decisions with legal or significant effect under Pasal 10, mirroring GDPR Article 22. Both rights are sometimes wrongly assumed missing from non-EU privacy laws; UU PDP has both.

Updates

Article published. As of this review, no primary source confirms the implementing PP or the Badan PDP Perpres has been signed; both remain in process.

Komdigi publicly restated a target of completing Badan PDP (the independent supervisory authority) in 2026, confirming the authority remains unestablished and that the ministry continues to handle oversight ad interim.

The draft Peraturan Presiden (Perpres) establishing Badan PDP entered harmonization at the Ministry of Law. Separately, the draft implementing Peraturan Pemerintah (RPP) reportedly finished its own harmonization process and roughly 1,989 rounds of public comment, and was reported sitting at the State Secretariat (Setneg) awaiting presidential signature as of that reporting.

The President granted izin prakarsa (initiative approval) to begin drafting the Perpres that will establish Badan PDP.

Perpres 174/2024 restructured the ministry overseeing UU PDP ad interim, renaming Kementerian Komunikasi dan Informatika (Kominfo) to Kementerian Komunikasi dan Digital (Komdigi), with a new Ditjen Pengawasan Ruang Digital handling PDP-related oversight duties.

UU PDP's two-year transition period ended. Every substantive obligation in the Law, legal-basis requirements, data subject rights, breach notification, cross-border transfer rules, and administrative and criminal penalties, became fully binding.

Sources and References

  1. Komdigi JDIH: Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP), full text(jdih.komdigi.go.id).gov
  2. Regulation (EU) 2016/679 (GDPR) Full Text(eur-lex.europa.eu).gov
  3. Hukumonline: Menanti Disahkannya Aturan Turunan UU PDP(hukumonline.com)
  4. Antara News Jatim: Komdigi restates Badan PDP 2026 completion target(jatim.antaranews.com)
Share: