How Long Can a Company Store Customer Data in Indonesia?

September 22, 2026 / Published by: Admin

How long a company can store customer personal data doesn’t have a single fixed answer, since the duration is set by the purpose the data was collected for, not by a company’s own internal policy. Once that purpose is fulfilled, the legal basis for continuing to hold the data disappears with it.

Indonesia’s Ministry of Communication and Informatics (Kominfo) made this principle public in the JD.ID shutdown case in 2023, publicly demanding that the e-commerce platform destroy all remaining customer data once it stopped operating in Indonesia. The reasoning was straightforward: personal data is collected for a specific purpose, and once that purpose no longer exists, the data must be deleted.

The trouble is that how long a company can store customer data often gets treated as one blanket answer, when it actually differs depending on whether a customer is active, inactive, or the company itself has shut down. This article walks through the legal basis, the practical estimates, and what happens once the retention period ends.

Legal Basis for Storing Customer Data in Indonesia

Storing customer data in Indonesia isn’t governed by a single law, since a general principle from the PDP Law applies alongside additional rules for certain industries. Both are explained below.

The PDP Law Principle: Data Is Deleted Once Its Purpose Ends

The legal basis sits in Article 16(2) of Indonesia’s Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), which requires personal data to be deleted once its retention period ends unless another law says otherwise, an obligation that, like the rest of the PDP Law, applies extraterritorially, so a foreign company processing the personal data of customers in Indonesia is bound by the same principle regardless of where it’s based. This principle means there’s no single figure like “one year” or “five years” that applies uniformly to every type of customer data.

Industries With Their Own Retention Rules

Some customer data isn’t governed by the PDP Law’s principle alone, since sectors such as banking, telecommunications, and taxation carry their own rules requiring longer retention. Indonesia’s anti-money-laundering regulation.

For instance, requires banks to maintain customer documentation for a set period, telecom operators are bound by usage-history retention requirements under Indonesia’s Telecommunications Law, and businesses subject to tax obligations must keep bookkeeping documents containing customer data under the Tax Law.

How Long Can Customer Data Actually Be Stored?

The answer depends on the customer’s relationship status with the company and which industry rules apply. Here’s the practical breakdown based on both factors.

It Comes Down to the Purpose of Processing

For customer data that isn’t subject to a specific industry rule, the answer comes back to the purpose behind processing it. As long as that purpose still applies, the data may be kept, and once it no longer applies, the obligation to delete it follows.

Estimated Retention by Stage of the Customer Relationship

How long customer data is stored shifts depending on the stage of the relationship, rather than being counted from when the data was first collected. Here are the 4 most common stages and their estimated retention.

1. Active customers
As long as a customer is still using the service, their data may be kept as long as it serves the original purpose of collection. Once that purpose expands, for example when transaction data starts being used for marketing that wasn’t agreed to upfront, the company needs to obtain additional consent.

2. Inactive customers with no formal account closure
A customer who stops transacting without formally closing their account sits in a grey area, since their data remains stored even as the original purpose starts to fade. Many companies set a grace period, such as two or three years of inactivity, before considering that data no longer needed.

3. After a formal account or relationship closure
Once a customer formally closes their account or ends the business relationship, data not tied to another legal obligation should start being scheduled for deletion. Data still tied to obligations such as tax or anti-money-laundering rules must still be kept for whatever period the relevant sector regulation sets.

4. After the company stops operating
Once a company permanently stops operating, all customer data with no remaining lawful processing purpose must be destroyed, exactly as happened in the JD.ID case. “It might be useful later” stops being a valid legal basis the moment operations are discontinued.

Estimates for Industries With Special Rules

For the industries mentioned in the legal basis section above, the estimates are more concrete than the PDP Law’s general principle. Banks are bound by customer documentation retention requirements running several years from when the business relationship ends, telecom operators follow usage-history retention obligations without one uniform figure, and businesses subject to tax rules must keep bookkeeping documents containing customer data for 10 years.

For a full walkthrough of building a retention policy from scratch, including how to reconcile the PDP Law’s principle with these industry-specific obligations, see our guide to building a company data retention policy.

Read also: What Makes a Good Website Privacy Policy Under the PDP Law

How Long Can Customer Data Actually Be Stored?

Company Obligations Once the Retention Period Ends

Once the retention period ends, a company’s obligation doesn’t stop at simply no longer using the data, it has to actually delete or destroy it. Moving data into passive, rarely accessed storage isn’t the same as lawfully deleting it.

The JD.ID shutdown is the clearest illustration of this, since Kominfo explicitly demanded destruction of the data, not just a stop to its use. A company that discontinues its operations, a single business line, or even one specific product remains bound by the same obligation once that data’s processing purpose no longer exists.

The deletion process should ideally be documented as compliance evidence, recording when and how the data was destroyed. That record becomes useful later if a regulator or a customer ever questions the status of their data.

Before deleting anything, it’s also worth confirming that no other sector-specific legal basis still requires retention, as covered earlier. Deleting data that turns out to still be legally required, under tax or financial regulation, for instance, just creates a new compliance problem.

Can a Customer Ask for Faster Deletion?

A customer’s deletion request still needs to be considered, but it can’t always be granted immediately. Banking is the clearest example, since a bank can’t delete a customer’s transaction data just because it’s requested, as long as that data remains subject to OJK’s documentation requirements.

In situations like this, the company still needs to explain the legal basis for why the data can’t be fully deleted yet. Once that mandatory retention period ends, the data can then genuinely be deleted per the customer’s original request.

Conclusion

How long a company can store customer data ultimately comes back to one simple question: does the original purpose for collecting it still apply? Once that purpose disappears, whether because a customer goes inactive, closes their account, or the company itself shuts down, the obligation to delete that data follows right behind it.

The most common mistake isn’t keeping data too briefly, it’s keeping it too long without a clear reason. Flagging and reviewing customer data on a regular schedule is far safer than waiting for an incident or a regulator’s letter to force the issue.

Ready to Manage Privacy Compliance as a Business Risk?

See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.

FAQ

Is there a universal maximum for how long customer data can be stored?

No universal figure exists, since the PDP Law bases retention on the purpose of processing rather than a fixed duration for every type of data.

What happens if a company keeps customer data with no clear purpose?

The company risks being found in breach of the PDP Law’s processing principles. That risk grows considerably if the data that piles up is later breached or misused.

Does inactive customer data have to be deleted automatically?

Not automatically, but a company should set a grace period before scheduling that data for deletion. Leaving it indefinitely just carries risk without any clear benefit.

What happens if a company changes its name or merges with another company?

Customer data can still be transferred as long as the purpose of processing doesn’t change and customers are informed of the change. A merger doesn’t remove the obligation to be transparent with customers about who now manages their data.

Who decides when customer data has passed its retention period?

Usually the compliance team or the data protection officer, based on a combination of the processing purpose and whatever sector rules apply. That decision is best not left to individual team members without clear guidance.

Profil Adaptist Consulting

Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.

Read Related Post