Sensitive Data in SEA: Comparing Indonesia’s PDP, EU GDPR, and Singapore’s PDPA

    August 31, 2026 / Published by: Admin

    Every major data protection law in Southeast Asia defines “sensitive data” differently. Indonesia treats financial records as sensitive. Singapore doesn’t recognize the category at all. The EU prohibits processing by default. We analyzed the primary statutory text of three jurisdictions, Indonesia’s UU PDP, the EU GDPR, and Singapore’s PDPA, and found that organizations applying a single global privacy template across these markets are non-compliant in at least two of them.

    We compared the data classification architectures, legal basis requirements, DPIA triggers, penalty structures, and enforcement status of the three regimes covering the period from 2020 through mid-2026. The result is a compliance landscape where the same dataset, a customer’s name, bank balance, and health record, requires three different legal justifications, three different consent mechanisms, and three different incident response workflows depending on where it’s processed.

    Summary

    The EU GDPR enforces a prohibition-by-default model: processing “special categories” of data under Article 9(1) is banned unless an explicit exemption under Article 9(2) is satisfied. Indonesia’s UU PDP takes a regulated-processing approach: personal data is split into “General” and “Specific” categories under Article 4, and processing Specific Personal Data, which includes financial records, requires explicit consent and mandatory Data Protection Impact Assessments. Singapore’s PDPA has no statutory sensitive data category at all: all personal data is treated uniformly, and data sensitivity is handled operationally through breach notification triggers.

    For multinationals, this means three things. First, your GDPR-compliant consent pop-up does not satisfy Indonesia’s Article 22 requirements. Second, Singapore’s breach notification window is 3 calendar days, shorter than both GDPR’s 72 hours and UU PDP’s 72 hours. Third, Indonesia’s list of “Specific Personal Data” is open-ended: Article 4(2)(g) allows sector-specific regulators to add new categories without parliamentary amendments, meaning your data taxonomy must be dynamically re-classifiable.

    Three Laws, Three Definitions, Zero Overlap

    The core problem is structural. Each jurisdiction classifies personal data using a different architecture:

    FeatureEU GDPRIndonesia UU PDPSingapore PDPA
    Classification ModelBipartite: Standard vs. Special CategoryBipartite: General vs. Specific DataUnitary: Flat single-tier definition
    Sensitive Data ListClosed / Exhaustive (Art. 9(1))Open-Ended (“data lainnya”, Art. 4(2)(g))Non-existent in main statute; prescribed in Schedule
    Financial DataStandard Personal DataSpecific Personal Data (Art. 4(2)(f))Standard Personal Data
    Primary Risk HookProcessing Prohibition & Lawful BasisMandatory DPIA & Explicit ConsentMandatory Breach Notification & Security
    Enforcement StatusActive (€6.31B+ cumulative fines)Partially untested (Lembaga PDP unformed)Active (breach timelines & security)

    The financial data classification is the most common compliance failure. EU-headquartered multinationals routinely assume personal financial data falls under standard Article 6 processing. In Indonesia, Article 4(2)(f) explicitly classifies personal financial data as Specific Personal Data, triggering explicit consent requirements under Article 22 and mandatory DPIAs under Article 34(2)(b). Processing Indonesian financial data without these controls is a statutory violation.

    What Each Law Actually Requires

    EU GDPR: Prohibition by Default

    Article 9(1) lists eight categories of special category data, and the list is closed, no additions are possible without legislative amendment:

    1. Racial or ethnic origin
    2. Political opinions
    3. Religious or philosophical beliefs
    4. Trade union membership
    5. Genetic data
    6. Biometric data processed for uniquely identifying a natural person
    7. Data concerning health
    8. Data concerning a natural person’s sex life or sexual orientation

    Processing is prohibited unless the entity satisfies both a legal basis under Article 6(1) and one of ten closed exemptions under Article 9(2): (a) explicit consent, (b) employment/social security obligations, (c) vital interests, (d) not-for-profit bodies, (e) manifestly made public by the data subject, (f) legal claims, (g) substantial public interest, (h) health/social care, (i) public health, and (j) archiving/research/statistics. The cumulative requirement is critical: an Article 6 legal basis (such as contract performance under Article 6(1)(b) or legitimate interests under Article 6(1)(f)) is necessary but not sufficient on its own; an Article 9(2) exception must also be satisfied.

    The Article 9(2)(e) exemption, “manifestly made public by the data subject” was tested in the Clearview AI case. The DPA ruled that public availability alone does not fulfill this exception; the data subject must have explicitly published the data for the specific type of processing being conducted. The EDPB ChatGPT Taskforce reinforced this: “the mere fact that personal data is publicly accessible does not imply that the data subject has manifestly made such data public.”

    The GDPR also separates criminal conviction data under Article 10, restricting its processing to official authority control or specific Member State legal authorizations. Financial data is omitted from Article 9 entirely, remaining governed by standard Article 6 legal bases. Biometric data is only classified under Article 9 when processed specifically to uniquely identify an individual, standard raw video footage does not trigger Article 9 protections unless facial recognition algorithms or biometric extraction tools are deployed.

    Indonesia UU PDP: Regulated Processing with Open-Ended Expansion

    Article 4(2) lists seven categories of Specific Personal Data: health data, biometric data, genetic data, criminal records, children’s data, personal financial data, and critically “other data in accordance with statutory provisions” under Article 4(2)(g). This open-ended gateway allows sector-specific regulators to designate new categories of Specific Personal Data without requiring parliamentary amendments.

    Processing Specific Personal Data under Article 22 requires explicit consent obtained via written or recorded electronic means. Article 34(2)(b) mandates a DPIA for any processing involving Specific Personal Data. Article 53 requires organizations meeting any of three conditions public interest processing, systematic large-scale monitoring, or large-scale processing of Specific Data to appoint a Data Protection Officer.

    The Lembaga PDP, the dedicated supervisory authority mandated under Article 58, has not been established as of mid-2026. Administrative fines of up to 2% of annual revenue under Article 57(3) remain structurally unavailable. Criminal penalties under Articles 67–68 carry prison terms of 4 to 6 years for intentional unlawful collection, disclosure, use, or falsification of personal data. Article 67(1) covers unlawful collection (up to 5 years, fine up to IDR 5 billion), Article 67(2) covers unlawful disclosure (up to 4 years, fine up to IDR 4 billion), Article 67(3) covers unlawful use (up to 5 years, fine up to IDR 5 billion), and Article 68 covers falsification (up to 6 years, fine up to IDR 6 billion). Corporate criminal liability under Article 70 extends to directors, controlling shareholders, and beneficial owners, with corporate fines up to 10 times the maximum individual fine.

    UU PDP Administrative Penalty Architecture (Article 57):

    Sanction TypeDescription
    Written warningsFormal notice of non-compliance
    Processing suspensionsTemporary or permanent ban on data processing activities
    Forced data erasureMandatory deletion of unlawfully processed data
    Administrative finesUp to 2% of annual revenue tied to the violation

    Enforcement of these sanctions requires both the Lembaga PDP and the implementing RPP PDP, neither of which is in place as of mid-2026.

    Singapore PDPA: No Sensitive Category, Operational Risk Triggers

    Singapore does not define a statutory category for sensitive personal data. Section 2(1) defines “personal data” uniformly. All personal data is governed by a general standard of reasonableness under Section 11 and a Protection Obligation under Section 24.

    Data sensitivity is handled operationally through the Personal Data Protection (Notification of Data Breaches) Regulations 2021. The Regulations define “prescribed personal data” combinations that trigger mandatory breach notifications: a breach relating to an individual’s full name, alias, or identification number together with any of the following categories:

    • Salary, wages, or income information
    • Financial account numbers, credit card details, and access credentials/PINs
    • Health and medical conditions, diagnoses, and treatment records
    • Biometric data and private keys used to authenticate electronic records
    • Information identifying children or young persons under the Children and Young Persons Act
    • Information identifying vulnerable adults under the Vulnerable Adults Act

    Additionally, a separate notification trigger exists where a breach involves both an account identifier (e.g., account name or number) and any password, security code, access code, biometric data, or other data used to allow access to that account. Compromising these data types creates a statutory presumption of “significant harm,” obligating notification to the PDPC and affected individuals within 3 calendar days after the organization assesses the breach as notifiable.

    In February 2026, the PDPC issued a directive requiring organizations to stop using NRIC numbers for identity authentication by 31 December 2026. This is an operational credential security mandate under Section 24, not a reclassification of national identifiers into a sensitive data category.

    Side by Side: How the Same Data Triggers Different Obligations

    Data TypeEU GDPR TreatmentIndonesia UU PDP TreatmentSingapore PDPA Treatment
    Health RecordsSpecial Category (Art. 9(1))Specific Personal Data (Art. 4(2)(a))Standard; Prescribed for Breach Duty
    Biometric DataSpecial Category only if for unique ID (Art. 9(1))Specific Personal Data (Art. 4(2)(b))Standard; Prescribed for Breach Duty
    Financial DataStandard (Art. 6)Specific Personal Data (Art. 4(2)(f))Standard; Prescribed for Breach Duty
    Children’s DataSeparate Consent Age Provision (Art. 8)Specific Personal Data (Art. 4(2)(e))Standard; Advisory Guideline (2024)
    Criminal HistorySegregated under Art. 10Specific Personal Data (Art. 4(2)(d))Standard
    Racial / Ethnic OriginSpecial Category (Art. 9(1))General Personal DataStandard
    Religious BeliefsSpecial Category (Art. 9(1))General Personal Data (Art. 4(3)(d))Standard
    National IDsStandardGeneral Personal DataStandard; Prescribed for Breach & Auth Ban

    The divergence on financial data is the critical compliance gap. A European bank operating in Indonesia cannot apply its GDPR data taxonomy to its Indonesian operations. Personal financial data account, balances, transaction histories, credit scores, is Specific Personal Data under UU PDP, requiring explicit consent and mandatory DPIAs. The same data is standard personal data under GDPR, governed by Article 6 legal bases.

    Operational Compliance: Three Different Playbooks

    ObligationEU GDPRIndonesia UU PDPSingapore PDPA
    Legal BasisArt. 9(2) closed list; Explicit Consent or narrow exemptionsArt. 22 written/recorded explicit consent; purpose-boundStandard consent, deemed consent, or legitimate interest
    DPIAMandatory under Art. 35(3)(b) for large-scale special dataMandatory under Art. 34(2)(b) for all Specific DataNon-statutory; encouraged by PDPC guidelines
    DPOMandatory (Art. 37(1)(c)) for large-scale special/criminal dataMandatory (Art. 53(1)) if any of three conditions metMandatory under S. 11(3) — all organizations
    Breach Notification72 hours to DPA (Art. 33)3 × 24 hours (72h) to Agency and Data Subjects (Art. 46)≤3 calendar days after assessment for prescribed data
    Children’s DataArt. 8 consent age (default 16; min 13)Art. 4(2)(e) Specific Data; Art. 25 parental consent mandatoryMarch 2024 Advisory; parental consent for <13

    Singapore’s 3-calendar-day breach notification window is tighter than both GDPR’s 72 hours and UU PDP’s 72 hours. Organizations must build separate incident response workflows for each jurisdiction, not a single global runbook.

    Enforcement: Active, Untested, and Active Again

    EU GDPR: €6.31 Billion and Counting

    Between May 2018 and August 2026, European Supervisory Authorities imposed over €6.31 billion in total GDPR fines. Annual penalty volumes reached approximately €1.2 billion in 2024 and 2025.

    GDPR Cumulative Fine Trajectory:

    PeriodCumulative TotalNotes
    2018–2020€0.3BEarly enforcement phase
    2021–2022€1.7BAcceleration
    2023€3.6BMajor fines compound
    2024–2025€5.7BAnnual run-rate ~€1.2B
    H1 2026€6.31B+H1 2026 additions ~€0.6B

    Landmark Article 9 cases include:

    CaseFineKey Finding
    Dutch DPA v. Uber (July 2024)€290MUnlawful transfer of driver data including medical records and criminal checks to U.S. servers
    Dutch DPA v. Clearview AI (Sept 2024)€30.5MPublic availability does not satisfy Art. 9(2)(e) unless data subject explicitly published for biometric processing
    Dutch DPA v. Municipalities (Feb 2026)€250KZero tolerance for public sector profiling based on religious beliefs
    CNIL v. IQVIA (May 2026)€5MPseudonymized health records retain Art. 9 status if re-identification risks remain

    Indonesia UU PDP: The Law Is Active. The Regulator Is Not.

    UU PDP became fully enforceable on October 17, 2024. But the Lembaga PDP mandated under Article 58 has not been established. Administrative fines under Article 57(3), up to 2% of annual revenue, cannot be issued until both the Lembaga and the implementing Government Regulation (RPP PDP) are in place.

    The Constitutional Court has become the de facto referee. Petition 153/PUU-XXIV/2026 was dismissed as inadmissible on June 17, 2026. A second petition (236/PUU-XXIV/2026) remains pending, seeking a judicial deadline for the Lembaga’s creation. Criminal provisions under Articles 67–68 are enforceable via courts regardless of the Lembaga’s status.

    Singapore PDPA: Operational Enforcement with Teeth

    Singapore’s PDPC actively enforces breach notification timelines and security obligations. The financial penalty ceiling under Section 48J is 10% of annual Singapore turnover for organizations exceeding S$10 million in turnover; otherwise up to S$1 million. Individual criminal liability under Sections 48D–48F carries penalties of up to S$200,000 fine and/or 2 years imprisonment.

    Enforcement Comparison:

    Regulatory MetricEU GDPRIndonesia UU PDPSingapore PDPA
    Supervisory BodyNational DPAs coordinated by EDPBLembaga PDP (Unformed as of mid-2026)PDPC
    Max Administrative Fine€20M or 4% of global annual turnoverUp to 2% of annual revenue tied to violation (Art. 57)10% of annual Singapore turnover (where >S$10M); otherwise S$1M
    Custodial PenaltiesNone under GDPR text (Member State criminal law varies)4 to 6 years imprisonment for intentional breaches (Arts. 67–69)Up to 2 years imprisonment for individual offenses
    Enforcement StatusActive (€6.31B+ cumulative fines through Aug 2026)Partially untested — administrative enforcement pending Lembaga; criminal provisions enforceable via courtsActive enforcement focused on breach timelines & security

    Our take: The dominant compliance assumption, that GDPR-level protections are the global ceiling, and everything else is simpler, is wrong in at least one direction. Indonesia treats financial data as sensitive. GDPR doesn’t. If you’re a European bank operating in Jakarta, your GDPR data taxonomy doesn’t just fail to cover Indonesian requirements, it actively misclassifies data that UU PDP treats with higher protection. The open-ended expansion gateway in Article 4(2)(g) means this gap will widen over time as sector regulators designate new categories. The fix isn’t a bigger global template. It’s three separate playbooks, maintained by people who read the primary statutory text in each jurisdiction, not the English translation of a summary.

    What You Should Do

    Five priorities for multinationals operating across EU, Indonesia, and Singapore:

    1. Re-engineer Financial Data Handling for Indonesia

    Personal financial data is Specific Personal Data under Article 4(2)(f) of UU PDP. This means explicit consent under Article 22 and mandatory DPIAs under Article 34(2)(b). If your global privacy system classifies financial data as standard personal data based on GDPR structures, it is non-compliant in Indonesia. Update data classification taxonomies to recognize jurisdiction-specific sensitive data definitions.

    2. Build Three Separate Incident Response Workflows

    Each jurisdiction has a different breach notification SLA: 72 hours (GDPR), 72 hours (UU PDP), and 3 calendar days (PDPA). But the notification triggers differ. GDPR requires notification for any breach likely to result in risk to individuals. UU PDP requires notification for any “kegagalan Pelindungan Data Pribadi.” PDPA requires notification only for “notifiable data breaches” involving prescribed data combinations. Build separate runbooks, not a single global template.

    3. Deploy Dynamic Data Tagging for Indonesia’s Open Expansion Gateway

    Article 4(2)(g) allows sector-specific regulators to expand the list of Specific Personal Data without parliamentary amendments. Configure automated data inventory systems to re-tag general personal data fields as specific personal data when new ministerial regulations take effect. A static data taxonomy will become outdated.

    4. Stop Applying GDPR Consent Pop-ups in Singapore

    The PDPA does not restrict processing based on statutory sensitive data categories. GDPR Article 9 explicit consent pop-ups applied to Singapore users create unnecessary friction and do not address the PDPA’s actual compliance requirements: breach notification under the 2021 Regulations, NRIC authentication phase-out by 31 December 2026, and the 2024 Children’s Advisory Guidelines. Focus Singapore compliance resources on incident response and credential security, not consent banners.

    5. Deploy Multi-Tiered Age Gating for Children’s Data

    Each jurisdiction handles children’s data differently. Indonesia classifies it as Specific Personal Data with mandatory parental consent under Article 25. The GDPR sets a default consent age of 16 with Member State flexibility down to 13 under Article 8. Singapore’s PDPC issued Advisory Guidelines in March 2024 recommending parental consent for under-13 with minor consent valid for 13–17 based on comprehension. Implement jurisdiction-specific age gating, not a single global age threshold.

    Methodology & Sources

    This analysis compares the primary statutory text of three data protection regimes: EU Regulation 2016/679 (GDPR), Indonesia Law No. 27 of 2022 (UU PDP), and Singapore’s Personal Data Protection Act 2012 (PDPA). Secondary sources include the PDPA’s Notification of Data Breach Regulations 2021, the PDPC’s 2024 Advisory Guidelines on Children’s Data, Constitutional Court decisions 153/PUU-XXIV/2026 and 236/PUU-XXIV/2026, and the enforcementtracker.com GDPR fine database.

    Key sources:

    • EUR-Lex: Regulation (EU) 2016/679, Articles 6, 8, 9, 10, 33, 35, 37, 83
    • Pasal.id: UU 27/2022, Articles 4, 20, 22, 25, 34, 46, 53, 57, 67–69
    • Datahukum.com: UU 27/2022, Articles 4(3), 20(2), 53(1)
    • Singapore Statutes Online: PDPA 2012, Sections 2(1), 11, 14, 24, 48D–48J
    • Singapore Statutes Online: Notification of Data Breach Regulations 2021, Part 6A, Schedule
    • Enforcementtracker.com: GDPR cumulative fine statistics (CMS Law Firm)
    • Autoriteit Persoonsgegevens: Dutch DPA v. Uber (July 2024), €290M fine
    • PwC Legal Belgium: Dutch DPA v. Clearview AI (September 2024), €30.5M fine
    • Mahkamah Konstitusi RI: Putusan 153/PUU-XXIV/2026 (dismissed Jun 17, 2026)
    • PDPC: NRIC authentication directive (February 2026), deadline Dec 31, 2026
    • Linklaters: PDPC Advisory Guidelines on Children’s Personal Data (March 2024)
    • GDPR-info.eu: Article 9 analysis and guidance

    All statutory references verified against primary source texts as of August 2026. Enforcement figures from enforcementtracker.com are cumulative through August 2026. Constitutional Court petition statuses are current as of mid-2026.


    Reference: Comparative Analysis of Sensitive Data Regimes: Indonesia PDP Law, EU GDPR, and Singapore PDPA for SEA Multinationals by Adaptist Consulting.


    Analysis conducted by Adaptist Consulting, August 2026. For questions about methodology or how these findings apply to your organization’s data governance infrastructure, contact us. 

    Profil Adaptist Consulting

    Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.