Every major data protection law in Southeast Asia defines “sensitive data” differently. Indonesia treats financial records as sensitive. Singapore doesn’t recognize the category at all. The EU prohibits processing by default. We analyzed the primary statutory text of three jurisdictions, Indonesia’s UU PDP, the EU GDPR, and Singapore’s PDPA, and found that organizations applying a single global privacy template across these markets are non-compliant in at least two of them.
We compared the data classification architectures, legal basis requirements, DPIA triggers, penalty structures, and enforcement status of the three regimes covering the period from 2020 through mid-2026. The result is a compliance landscape where the same dataset, a customer’s name, bank balance, and health record, requires three different legal justifications, three different consent mechanisms, and three different incident response workflows depending on where it’s processed.
Summary
The EU GDPR enforces a prohibition-by-default model: processing “special categories” of data under Article 9(1) is banned unless an explicit exemption under Article 9(2) is satisfied. Indonesia’s UU PDP takes a regulated-processing approach: personal data is split into “General” and “Specific” categories under Article 4, and processing Specific Personal Data, which includes financial records, requires explicit consent and mandatory Data Protection Impact Assessments. Singapore’s PDPA has no statutory sensitive data category at all: all personal data is treated uniformly, and data sensitivity is handled operationally through breach notification triggers.
For multinationals, this means three things. First, your GDPR-compliant consent pop-up does not satisfy Indonesia’s Article 22 requirements. Second, Singapore’s breach notification window is 3 calendar days, shorter than both GDPR’s 72 hours and UU PDP’s 72 hours. Third, Indonesia’s list of “Specific Personal Data” is open-ended: Article 4(2)(g) allows sector-specific regulators to add new categories without parliamentary amendments, meaning your data taxonomy must be dynamically re-classifiable.
Three Laws, Three Definitions, Zero Overlap
The core problem is structural. Each jurisdiction classifies personal data using a different architecture:
| Feature | EU GDPR | Indonesia UU PDP | Singapore PDPA |
|---|---|---|---|
| Classification Model | Bipartite: Standard vs. Special Category | Bipartite: General vs. Specific Data | Unitary: Flat single-tier definition |
| Sensitive Data List | Closed / Exhaustive (Art. 9(1)) | Open-Ended (“data lainnya”, Art. 4(2)(g)) | Non-existent in main statute; prescribed in Schedule |
| Financial Data | Standard Personal Data | Specific Personal Data (Art. 4(2)(f)) | Standard Personal Data |
| Primary Risk Hook | Processing Prohibition & Lawful Basis | Mandatory DPIA & Explicit Consent | Mandatory Breach Notification & Security |
| Enforcement Status | Active (€6.31B+ cumulative fines) | Partially untested (Lembaga PDP unformed) | Active (breach timelines & security) |
The financial data classification is the most common compliance failure. EU-headquartered multinationals routinely assume personal financial data falls under standard Article 6 processing. In Indonesia, Article 4(2)(f) explicitly classifies personal financial data as Specific Personal Data, triggering explicit consent requirements under Article 22 and mandatory DPIAs under Article 34(2)(b). Processing Indonesian financial data without these controls is a statutory violation.
What Each Law Actually Requires
EU GDPR: Prohibition by Default
Article 9(1) lists eight categories of special category data, and the list is closed, no additions are possible without legislative amendment:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data processed for uniquely identifying a natural person
- Data concerning health
- Data concerning a natural person’s sex life or sexual orientation
Processing is prohibited unless the entity satisfies both a legal basis under Article 6(1) and one of ten closed exemptions under Article 9(2): (a) explicit consent, (b) employment/social security obligations, (c) vital interests, (d) not-for-profit bodies, (e) manifestly made public by the data subject, (f) legal claims, (g) substantial public interest, (h) health/social care, (i) public health, and (j) archiving/research/statistics. The cumulative requirement is critical: an Article 6 legal basis (such as contract performance under Article 6(1)(b) or legitimate interests under Article 6(1)(f)) is necessary but not sufficient on its own; an Article 9(2) exception must also be satisfied.
The Article 9(2)(e) exemption, “manifestly made public by the data subject” was tested in the Clearview AI case. The DPA ruled that public availability alone does not fulfill this exception; the data subject must have explicitly published the data for the specific type of processing being conducted. The EDPB ChatGPT Taskforce reinforced this: “the mere fact that personal data is publicly accessible does not imply that the data subject has manifestly made such data public.”
The GDPR also separates criminal conviction data under Article 10, restricting its processing to official authority control or specific Member State legal authorizations. Financial data is omitted from Article 9 entirely, remaining governed by standard Article 6 legal bases. Biometric data is only classified under Article 9 when processed specifically to uniquely identify an individual, standard raw video footage does not trigger Article 9 protections unless facial recognition algorithms or biometric extraction tools are deployed.
Indonesia UU PDP: Regulated Processing with Open-Ended Expansion
Article 4(2) lists seven categories of Specific Personal Data: health data, biometric data, genetic data, criminal records, children’s data, personal financial data, and critically “other data in accordance with statutory provisions” under Article 4(2)(g). This open-ended gateway allows sector-specific regulators to designate new categories of Specific Personal Data without requiring parliamentary amendments.
Processing Specific Personal Data under Article 22 requires explicit consent obtained via written or recorded electronic means. Article 34(2)(b) mandates a DPIA for any processing involving Specific Personal Data. Article 53 requires organizations meeting any of three conditions public interest processing, systematic large-scale monitoring, or large-scale processing of Specific Data to appoint a Data Protection Officer.
The Lembaga PDP, the dedicated supervisory authority mandated under Article 58, has not been established as of mid-2026. Administrative fines of up to 2% of annual revenue under Article 57(3) remain structurally unavailable. Criminal penalties under Articles 67–68 carry prison terms of 4 to 6 years for intentional unlawful collection, disclosure, use, or falsification of personal data. Article 67(1) covers unlawful collection (up to 5 years, fine up to IDR 5 billion), Article 67(2) covers unlawful disclosure (up to 4 years, fine up to IDR 4 billion), Article 67(3) covers unlawful use (up to 5 years, fine up to IDR 5 billion), and Article 68 covers falsification (up to 6 years, fine up to IDR 6 billion). Corporate criminal liability under Article 70 extends to directors, controlling shareholders, and beneficial owners, with corporate fines up to 10 times the maximum individual fine.
UU PDP Administrative Penalty Architecture (Article 57):
| Sanction Type | Description |
|---|---|
| Written warnings | Formal notice of non-compliance |
| Processing suspensions | Temporary or permanent ban on data processing activities |
| Forced data erasure | Mandatory deletion of unlawfully processed data |
| Administrative fines | Up to 2% of annual revenue tied to the violation |
Enforcement of these sanctions requires both the Lembaga PDP and the implementing RPP PDP, neither of which is in place as of mid-2026.
Singapore PDPA: No Sensitive Category, Operational Risk Triggers
Singapore does not define a statutory category for sensitive personal data. Section 2(1) defines “personal data” uniformly. All personal data is governed by a general standard of reasonableness under Section 11 and a Protection Obligation under Section 24.
Data sensitivity is handled operationally through the Personal Data Protection (Notification of Data Breaches) Regulations 2021. The Regulations define “prescribed personal data” combinations that trigger mandatory breach notifications: a breach relating to an individual’s full name, alias, or identification number together with any of the following categories:
- Salary, wages, or income information
- Financial account numbers, credit card details, and access credentials/PINs
- Health and medical conditions, diagnoses, and treatment records
- Biometric data and private keys used to authenticate electronic records
- Information identifying children or young persons under the Children and Young Persons Act
- Information identifying vulnerable adults under the Vulnerable Adults Act
Additionally, a separate notification trigger exists where a breach involves both an account identifier (e.g., account name or number) and any password, security code, access code, biometric data, or other data used to allow access to that account. Compromising these data types creates a statutory presumption of “significant harm,” obligating notification to the PDPC and affected individuals within 3 calendar days after the organization assesses the breach as notifiable.
In February 2026, the PDPC issued a directive requiring organizations to stop using NRIC numbers for identity authentication by 31 December 2026. This is an operational credential security mandate under Section 24, not a reclassification of national identifiers into a sensitive data category.
Side by Side: How the Same Data Triggers Different Obligations
| Data Type | EU GDPR Treatment | Indonesia UU PDP Treatment | Singapore PDPA Treatment |
|---|---|---|---|
| Health Records | Special Category (Art. 9(1)) | Specific Personal Data (Art. 4(2)(a)) | Standard; Prescribed for Breach Duty |
| Biometric Data | Special Category only if for unique ID (Art. 9(1)) | Specific Personal Data (Art. 4(2)(b)) | Standard; Prescribed for Breach Duty |
| Financial Data | Standard (Art. 6) | Specific Personal Data (Art. 4(2)(f)) | Standard; Prescribed for Breach Duty |
| Children’s Data | Separate Consent Age Provision (Art. 8) | Specific Personal Data (Art. 4(2)(e)) | Standard; Advisory Guideline (2024) |
| Criminal History | Segregated under Art. 10 | Specific Personal Data (Art. 4(2)(d)) | Standard |
| Racial / Ethnic Origin | Special Category (Art. 9(1)) | General Personal Data | Standard |
| Religious Beliefs | Special Category (Art. 9(1)) | General Personal Data (Art. 4(3)(d)) | Standard |
| National IDs | Standard | General Personal Data | Standard; Prescribed for Breach & Auth Ban |
The divergence on financial data is the critical compliance gap. A European bank operating in Indonesia cannot apply its GDPR data taxonomy to its Indonesian operations. Personal financial data account, balances, transaction histories, credit scores, is Specific Personal Data under UU PDP, requiring explicit consent and mandatory DPIAs. The same data is standard personal data under GDPR, governed by Article 6 legal bases.
Operational Compliance: Three Different Playbooks
| Obligation | EU GDPR | Indonesia UU PDP | Singapore PDPA |
|---|---|---|---|
| Legal Basis | Art. 9(2) closed list; Explicit Consent or narrow exemptions | Art. 22 written/recorded explicit consent; purpose-bound | Standard consent, deemed consent, or legitimate interest |
| DPIA | Mandatory under Art. 35(3)(b) for large-scale special data | Mandatory under Art. 34(2)(b) for all Specific Data | Non-statutory; encouraged by PDPC guidelines |
| DPO | Mandatory (Art. 37(1)(c)) for large-scale special/criminal data | Mandatory (Art. 53(1)) if any of three conditions met | Mandatory under S. 11(3) — all organizations |
| Breach Notification | 72 hours to DPA (Art. 33) | 3 × 24 hours (72h) to Agency and Data Subjects (Art. 46) | ≤3 calendar days after assessment for prescribed data |
| Children’s Data | Art. 8 consent age (default 16; min 13) | Art. 4(2)(e) Specific Data; Art. 25 parental consent mandatory | March 2024 Advisory; parental consent for <13 |
Singapore’s 3-calendar-day breach notification window is tighter than both GDPR’s 72 hours and UU PDP’s 72 hours. Organizations must build separate incident response workflows for each jurisdiction, not a single global runbook.
Enforcement: Active, Untested, and Active Again
EU GDPR: €6.31 Billion and Counting
Between May 2018 and August 2026, European Supervisory Authorities imposed over €6.31 billion in total GDPR fines. Annual penalty volumes reached approximately €1.2 billion in 2024 and 2025.
GDPR Cumulative Fine Trajectory:
| Period | Cumulative Total | Notes |
|---|---|---|
| 2018–2020 | €0.3B | Early enforcement phase |
| 2021–2022 | €1.7B | Acceleration |
| 2023 | €3.6B | Major fines compound |
| 2024–2025 | €5.7B | Annual run-rate ~€1.2B |
| H1 2026 | €6.31B+ | H1 2026 additions ~€0.6B |
Landmark Article 9 cases include:
| Case | Fine | Key Finding |
|---|---|---|
| Dutch DPA v. Uber (July 2024) | €290M | Unlawful transfer of driver data including medical records and criminal checks to U.S. servers |
| Dutch DPA v. Clearview AI (Sept 2024) | €30.5M | Public availability does not satisfy Art. 9(2)(e) unless data subject explicitly published for biometric processing |
| Dutch DPA v. Municipalities (Feb 2026) | €250K | Zero tolerance for public sector profiling based on religious beliefs |
| CNIL v. IQVIA (May 2026) | €5M | Pseudonymized health records retain Art. 9 status if re-identification risks remain |
Indonesia UU PDP: The Law Is Active. The Regulator Is Not.
UU PDP became fully enforceable on October 17, 2024. But the Lembaga PDP mandated under Article 58 has not been established. Administrative fines under Article 57(3), up to 2% of annual revenue, cannot be issued until both the Lembaga and the implementing Government Regulation (RPP PDP) are in place.
The Constitutional Court has become the de facto referee. Petition 153/PUU-XXIV/2026 was dismissed as inadmissible on June 17, 2026. A second petition (236/PUU-XXIV/2026) remains pending, seeking a judicial deadline for the Lembaga’s creation. Criminal provisions under Articles 67–68 are enforceable via courts regardless of the Lembaga’s status.
Singapore PDPA: Operational Enforcement with Teeth
Singapore’s PDPC actively enforces breach notification timelines and security obligations. The financial penalty ceiling under Section 48J is 10% of annual Singapore turnover for organizations exceeding S$10 million in turnover; otherwise up to S$1 million. Individual criminal liability under Sections 48D–48F carries penalties of up to S$200,000 fine and/or 2 years imprisonment.
Enforcement Comparison:
| Regulatory Metric | EU GDPR | Indonesia UU PDP | Singapore PDPA |
|---|---|---|---|
| Supervisory Body | National DPAs coordinated by EDPB | Lembaga PDP (Unformed as of mid-2026) | PDPC |
| Max Administrative Fine | €20M or 4% of global annual turnover | Up to 2% of annual revenue tied to violation (Art. 57) | 10% of annual Singapore turnover (where >S$10M); otherwise S$1M |
| Custodial Penalties | None under GDPR text (Member State criminal law varies) | 4 to 6 years imprisonment for intentional breaches (Arts. 67–69) | Up to 2 years imprisonment for individual offenses |
| Enforcement Status | Active (€6.31B+ cumulative fines through Aug 2026) | Partially untested — administrative enforcement pending Lembaga; criminal provisions enforceable via courts | Active enforcement focused on breach timelines & security |
Our take: The dominant compliance assumption, that GDPR-level protections are the global ceiling, and everything else is simpler, is wrong in at least one direction. Indonesia treats financial data as sensitive. GDPR doesn’t. If you’re a European bank operating in Jakarta, your GDPR data taxonomy doesn’t just fail to cover Indonesian requirements, it actively misclassifies data that UU PDP treats with higher protection. The open-ended expansion gateway in Article 4(2)(g) means this gap will widen over time as sector regulators designate new categories. The fix isn’t a bigger global template. It’s three separate playbooks, maintained by people who read the primary statutory text in each jurisdiction, not the English translation of a summary.
What You Should Do
Five priorities for multinationals operating across EU, Indonesia, and Singapore:
1. Re-engineer Financial Data Handling for Indonesia
Personal financial data is Specific Personal Data under Article 4(2)(f) of UU PDP. This means explicit consent under Article 22 and mandatory DPIAs under Article 34(2)(b). If your global privacy system classifies financial data as standard personal data based on GDPR structures, it is non-compliant in Indonesia. Update data classification taxonomies to recognize jurisdiction-specific sensitive data definitions.
2. Build Three Separate Incident Response Workflows
Each jurisdiction has a different breach notification SLA: 72 hours (GDPR), 72 hours (UU PDP), and 3 calendar days (PDPA). But the notification triggers differ. GDPR requires notification for any breach likely to result in risk to individuals. UU PDP requires notification for any “kegagalan Pelindungan Data Pribadi.” PDPA requires notification only for “notifiable data breaches” involving prescribed data combinations. Build separate runbooks, not a single global template.
3. Deploy Dynamic Data Tagging for Indonesia’s Open Expansion Gateway
Article 4(2)(g) allows sector-specific regulators to expand the list of Specific Personal Data without parliamentary amendments. Configure automated data inventory systems to re-tag general personal data fields as specific personal data when new ministerial regulations take effect. A static data taxonomy will become outdated.
4. Stop Applying GDPR Consent Pop-ups in Singapore
The PDPA does not restrict processing based on statutory sensitive data categories. GDPR Article 9 explicit consent pop-ups applied to Singapore users create unnecessary friction and do not address the PDPA’s actual compliance requirements: breach notification under the 2021 Regulations, NRIC authentication phase-out by 31 December 2026, and the 2024 Children’s Advisory Guidelines. Focus Singapore compliance resources on incident response and credential security, not consent banners.
5. Deploy Multi-Tiered Age Gating for Children’s Data
Each jurisdiction handles children’s data differently. Indonesia classifies it as Specific Personal Data with mandatory parental consent under Article 25. The GDPR sets a default consent age of 16 with Member State flexibility down to 13 under Article 8. Singapore’s PDPC issued Advisory Guidelines in March 2024 recommending parental consent for under-13 with minor consent valid for 13–17 based on comprehension. Implement jurisdiction-specific age gating, not a single global age threshold.
Methodology & Sources
This analysis compares the primary statutory text of three data protection regimes: EU Regulation 2016/679 (GDPR), Indonesia Law No. 27 of 2022 (UU PDP), and Singapore’s Personal Data Protection Act 2012 (PDPA). Secondary sources include the PDPA’s Notification of Data Breach Regulations 2021, the PDPC’s 2024 Advisory Guidelines on Children’s Data, Constitutional Court decisions 153/PUU-XXIV/2026 and 236/PUU-XXIV/2026, and the enforcementtracker.com GDPR fine database.
Key sources:
- EUR-Lex: Regulation (EU) 2016/679, Articles 6, 8, 9, 10, 33, 35, 37, 83
- Pasal.id: UU 27/2022, Articles 4, 20, 22, 25, 34, 46, 53, 57, 67–69
- Datahukum.com: UU 27/2022, Articles 4(3), 20(2), 53(1)
- Singapore Statutes Online: PDPA 2012, Sections 2(1), 11, 14, 24, 48D–48J
- Singapore Statutes Online: Notification of Data Breach Regulations 2021, Part 6A, Schedule
- Enforcementtracker.com: GDPR cumulative fine statistics (CMS Law Firm)
- Autoriteit Persoonsgegevens: Dutch DPA v. Uber (July 2024), €290M fine
- PwC Legal Belgium: Dutch DPA v. Clearview AI (September 2024), €30.5M fine
- Mahkamah Konstitusi RI: Putusan 153/PUU-XXIV/2026 (dismissed Jun 17, 2026)
- PDPC: NRIC authentication directive (February 2026), deadline Dec 31, 2026
- Linklaters: PDPC Advisory Guidelines on Children’s Personal Data (March 2024)
- GDPR-info.eu: Article 9 analysis and guidance
All statutory references verified against primary source texts as of August 2026. Enforcement figures from enforcementtracker.com are cumulative through August 2026. Constitutional Court petition statuses are current as of mid-2026.
Reference: Comparative Analysis of Sensitive Data Regimes: Indonesia PDP Law, EU GDPR, and Singapore PDPA for SEA Multinationals by Adaptist Consulting.
Analysis conducted by Adaptist Consulting, August 2026. For questions about methodology or how these findings apply to your organization’s data governance infrastructure, contact us.
