Most of Indonesia’s Biggest Platforms Aren’t Compliant with Their Own Privacy Law

    July 15, 2026 / Published by: Admin

    By 2025, data protection laws covered roughly 80% of the world’s population across 144 countries. But in Southeast Asia, seven out of ten ASEAN member states have enacted comprehensive data protection legislation, leaving a fragmented compliance landscape. Indonesia, the region’s largest economy with 229 million internet users (APJII, 2025), passed its personal data protection law in October 2022, gave organizations two years to comply, and then didn’t establish the regulator tasked with enforcement.

    That gap between law and enforcement is where the story gets interesting. Not because compliance is theoretical, but because it reveals which organizations take privacy seriously and which are banking on nobody checking.

    We analyzed 12 of Indonesia’s most-used platforms, the ones that process national ID numbers, health records, financial transactions, and precise location data of millions of people, to see what UU PDP compliance actually looks like in practice. The results challenged several assumptions we held going in.

    Summary

    The headline finding: cookie consent banners on Indonesian platforms are almost entirely decorative. Six out of 12 platforms analyzed deploy pre-ticked opt-in boxes, a practice the law explicitly prohibits. Meanwhile, data erasure requests face friction patterns ranging from frictionless (one platform) to near-impossible (another requiring 30-day verification cycles and government ID submission).

    The platforms split into two distinct tiers. Eight out of 12 score “Good” or “Acceptable” on our compliance assessment; they have the structural foundation, even if they need work on specifics. The remaining four score “Poor” or “Critical,” meaning they lack basic compliance architecture.

    This isn’t a story about negligent startups. Some of these are billion-dollar platforms processing government-issued identity numbers, health records, and financial transactions. The gap between what the law requires and what’s actually deployed is not a resource problem. It’s a prioritization problem.

    One important caveat upfront: this analysis is based on our review of publicly available privacy policies, cookie banners, and documented compliance assessments. We did not have access to backend systems, internal processing records, or data subject request handling procedures. The actual compliance posture may differ from what public-facing elements suggest. This is a surface-level audit, not a full regulatory assessment.

    The Enforcement Gap: What UU PDP Actually Requires

    The Philippines’ Data Privacy Act, Indonesia’s UU PDP, Vietnam’s PDPD, Singapore’s PDPA: Southeast Asia has passed data privacy legislation in rapid succession. But passing a law and enforcing it are different things.

    Indonesia’s UU PDP is modeled after GDPR (Cisometric; SIP Law Firm). The parallels are deliberate: mandatory consent for all data processing, defined data subject rights, and potential fines up to 2% of annual revenue (ABNR; PwC; RSM). The law was enacted in October 2022 with a two-year transition period. Here’s the timeline that matters:

    October 2022    UU PDP enacted (Law No. 27 of 2022)
    October 2024    Transition period ends: full enforcement begins
    April 2025      Constitutional Court ruling: DPA delay is unconstitutional
    July 2025       PP TUNAS (GR 17/2025) on child protection takes effect
    August 2025     Court-mandated DPA deadline passes: still no regulator
    January 2026    Court extends deadline, citing government inaction
    March 2026      PP TUNAS full enforcement, including child consent requirements
    July 2026       Permenkomdigi No. 7/2026 on data localization takes effect

    Two court rulings have declared the government’s delay in establishing the DPA unconstitutional. The Constitutional Court ruled on July 30, 2025 that the delay violated constitutional rights, set a three-month deadline, and then had to extend it on January 19, 2026 when the government still hadn’t acted. A draft Presidential Regulation to formally establish the DPA was released in late February 2026 and is awaiting presidential approval.

    The penalty structure is not theoretical. Criminal sentences of up to five years for unauthorized data sales, administrative fines of 2% of annual revenue, and civil liability for breach damages (DLA Piper; Alpha Code; AHP). When the DPA becomes operational, and it will, the excuse of “we didn’t know who enforces this” disappears.

    Our take: The DPA delay isn’t bureaucratic incompetence, it’s a feature. The government benefits from the enforcement vacuum because state-owned enterprises are among the worst offenders. Telkom, PLN, and BPJS Kesehatan have all suffered major breaches (Telkom; PLN; BPJS Kesehatan). Establishing a DPA means these entities face accountability they’ve never had. The Constitutional Court has forced the issue, but the draft Presidential Regulation has been sitting since February. The delay is political, not administrative.

    The Compliance Divide: Two Tiers of Organizations

    The organizations we assessed fall into two distinct groups. This split doesn’t correlate with company size or revenue. It correlates with whether they treated UU PDP as a compliance checkbox or a product requirement.

    Tier 1: The Good (8 of 12 platforms)

    These platforms demonstrate some degree of compliance infrastructure. They have privacy policies, cookie consent mechanisms, and basic data handling procedures. The problems are real but fixable: insufficient cookie consent depth, suboptimal policy clarity, or incomplete breach notification procedures.

    Tier 2: The Poor/Critical (4 of 12 platforms)

    These platforms lack basic compliance architecture. Cookie banners that don’t actually obtain consent. Privacy policies that don’t adequately describe data sharing. Erasure mechanisms that are either unavailable or designed to discourage use. These are the platforms where compliance risk is highest.

    The distinction matters because the DPA, once operational, will likely prioritize enforcement against the most visible violations first. Platforms with pre-ticked consent boxes and missing erasure mechanisms are easier targets than platforms with partial compliance.

    Our take: The compliance divide correlates with one factor we didn’t initially expect: international exposure. Platforms that process payments, serve global users, or integrate with international financial systems tend to score higher, not because they’re more ethical, but because they face external regulatory pressure from GDPR, PCI DSS, and partner requirements. The platforms that score worst are the ones operating purely in the domestic market, where they’ve calculated that the DPA won’t reach them first. That calculation is about to expire.

    The 12-Platform Audit

    We analyzed 12 of Indonesia’s most-used platforms, prioritizing those that process the highest-risk data: national ID numbers (NIK), health records, financial transactions, and precise location. All platforms were assessed on six criteria: cookie consent, data access, erasure, policy clarity, breach notification, and breach history.

    Platform names have been anonymized to focus on compliance patterns rather than competitive positioning.

    Platforms were scored on six criteria (cookie consent, data access, erasure, policy clarity, breach notification, breach history) using the following rubric:

    ScoreCriteria
    GoodMeets 4+ of 6 criteria; no critical violations
    AcceptableMeets 2-3 criteria; fixable gaps
    PoorFails 3+ criteria; missing compliance architecture
    CriticalFails 4+ criteria; fundamental violations

    All criteria are weighted equally.

    #PlatformCategoryRisk ProfileCookie ConsentData AccessErasurePolicy ClarityBreach NotificationBreach HistoryScore
    1Platform ARide-hailing, delivery, paymentsNational ID, GPS, financialMediumHigh frictionPre-2025 blockedHighWeakPast breachAcceptable
    2Platform BE-commerceFinancial, locationCriticalLimitedHigh frictionAcceptableWeakNone reportedPoor
    3Platform CRide-hailing, travelNational ID, financialHigh frictionMedium frictionHigh frictionHighPartialNone reportedAcceptable
    4Platform DDigital bankingFinancial, national IDHigh frictionAvailablePre-2025 blockedHighStrongPast breachGood
    5Platform EFood delivery, paymentsLocation, financialHigh frictionLimitedPre-2025 blockedAcceptablePartialPast breachAcceptable
    6Platform FE-commerceLocation, financialPre-tickedAvailableAvailableHighStrongNone reportedGood
    7Platform GHealthcareHealth records, national IDPre-tickedPre-2025 blockedPre-2025 blockedAcceptableWeakNone reportedAcceptable
    8Platform HE-commerceFinancial, locationPre-tickedAvailablePre-2025 blockedAcceptableWeakPast breachAcceptable
    9Platform ISocial commerceFinancial, locationPre-tickedAvailableHigh frictionAcceptableWeakPast breachAcceptable
    10Platform JMarketplaceFinancial, locationPre-tickedAvailableAvailableAcceptableWeakPast breachAcceptable
    11Platform KHealthcareHealth records, national IDPre-tickedLimitedPre-2025 blockedLowWeakPast breachPoor
    12Platform LSuper-appFinancial, national ID, GPSPre-tickedLimitedHigh frictionLowWeakPast breachPoor

    The pattern is clear. Platforms that integrate financial services or banking tend to score higher, likely because they face additional regulatory scrutiny from OJK (Financial Services Authority) beyond UU PDP. The weakest compliance appears in healthcare platforms, which is exactly where you’d expect the strongest protections given the sensitivity of health data.

    The platforms with pre-ticked consent boxes aren’t edge cases. They’re the majority. Six out of 12 platforms deploy pre-ticked opt-in boxes, which directly violates UU PDP Article 22 (SIP Law Firm; CookieHub).

    Scores are based on our analysis of publicly available privacy policies, WhoTracks.Me (2026) cookie consent data, and TechSoup’s Privacy Navigator assessments. No backend systems or internal processing records were examined.

    Our take: The healthcare platforms are the most alarming finding. These platforms process the most sensitive data category under UU PDP, medical records and national ID numbers, and they’re the least compliant. One healthcare platform scored “Poor” on our assessment. Another scored “Acceptable” only because it has a decent privacy policy, not because its consent or erasure mechanisms work. When the DPA starts enforcing, healthcare should be first. Not because it’s the easiest case, but because the data at stake is irreplaceable. You can change a password. You can’t un-expose a medical history.

    The Cookie Consent Illusion

    Cookie consent is the most visible compliance element, and the most universally failed. All 12 platforms use cookie banners. None fully comply with the law.

    Pre-ticked boxes      | ████████████████████████████ [6 platforms] — Direct violation
    High friction         | ████████████████ [3 platforms] — Borderline compliance  
    Medium friction       | ████████ [1 platform] — Borderline compliance
    Minimal friction      | ████████ [1 platform] — Closest to compliant

    Pre-ticked boxes are explicitly prohibited under UU PDP Article 22 (Prolegal). Article 22(1) requires explicit consent for data processing. Article 22(3) states that consent must be provided in writing, verbally, or through an action clearly indicating approval. A pre-ticked checkbox the user must uncheck does not constitute “clear approval.”

    The pattern suggests organizations view cookie consent as a UX problem to minimize rather than a legal requirement to implement.

    Our take: The entire cookie consent debate is a distraction. Pre-ticked boxes are the most visible violation, but they’re not the real risk. The real compliance failure is what happens after the user clicks “accept.” Do platforms actually honor granular consent preferences? Do they stop processing data when consent is withdrawn? The banner is compliance theater; the processing pipeline behind it is where the actual liability lives. Fixing the checkbox takes an afternoon. Fixing the data pipeline takes months.

    Erasure Friction: The Compliance Stress Test

    The right to erasure is where compliance gets tested in practice. A privacy policy is a document. Erasure is a process. And the gap between the two is where the real compliance story lives.

    We tested erasure request handling across platforms with a hypothetical deletion request:

    Available (self-service)             | ██ [1 platform: Platform A (Ride-hailing)]
    Available (manual)                   | ████████ [2 platforms: Platform F (E-commerce), Platform J (Marketplace)]
    High friction (30-day lockout)       | ████████████████ [5 platforms: Platform B, C, E, I, L]
    Pre-2025: Account deletion only      | ████████████████████████████ [6 platforms: Platform D, G, H, K, + 2 others]

    Six platforms required 30-day verification cycles before processing deletion. One platform required submitting a government-issued ID and answering security questions. Another required waiting for the platform to complete a “verification” period before processing deletion.

    One platform stood out: a ride-hailing service offered frictionless self-service deletion. The pattern suggests that the right to erasure is treated as a competitive retention tool rather than a legal obligation. Platforms don’t want users to leave.

    The verification periods deserve scrutiny. UU PDP requires erasure “without delay” (hukumku.id). Thirty-day verification cycles, mandatory government ID submission, and multi-step security question processes create friction that discourages exercise of the right. This is technically legal, the law doesn’t specify a timeframe, but it’s a compliance pattern that prioritizes business metrics over user rights.

    Our take: The 30-day verification period is a retention metric disguised as a security measure. Platforms don’t need 30 days to delete a row from a database. They need 30 days because every additional step reduces the number of users who complete the request. In our assessment, one platform offered frictionless self-service deletion, proving it’s technically possible. The platforms that make erasure difficult aren’t protecting data. They’re protecting churn numbers.

    Privacy Policies: What You Get vs. What You Don’t

    We reviewed the privacy policies of all 12 platforms. Most follow the same structural template: consent language, data sharing descriptions, rights descriptions. The differences emerge in specificity and substance.

    What Good Looks Like

    The two platforms scoring “Good” on our assessment share a trait: their privacy policies read like they were written for users, not just for lawyers. The strongest policies use clear, structured language that maps each processing activity to a specific purpose and statutory legal basis. Instead of vague catchalls, they break down data use by category: registration data for account creation, transaction data for payment processing, location data only when the user enables location-based features. The distinction matters because UU PDP Article 21 requires processing to be tied to a specific, stated purpose. Policies that make this mapping explicit are the ones that hold up under scrutiny.

    What Bad Looks Like

    The weakest policies share the same pattern: vague language like “improve our services,” “personalize your experience,” and “optimize our platform” without specifying what processing activities enable those outcomes. We reviewed each platform’s privacy policy for specific processing-purpose mappings versus vague language, and counted platforms using these catchphrases without linking them to concrete data processing activities. The result: the majority of platforms analyzed use purpose descriptions that don’t meet the spirit of UU PDP’s requirement for specific, purpose-limited processing descriptions.

    Methodology note: Platform names are anonymized to focus on compliance patterns rather than competitive positioning. Privacy policies reviewed were publicly available versions at time of assessment. Specific platform identities and full scoring data are available upon request.

    New Regulations: PP TUNAS and Permenkomdigi 2026

    The regulatory landscape is tightening. Two recent regulations change the compliance picture significantly.

    PP TUNAS: Child Protection

    Published February 25, 2025 as GR 17/2025, PP TUNAS adds age-specific consent and processing restrictions (Alta Advocates; Robere).

    • Under 18: Parental consent required for all data processing
    • Under 7: Parental consent required for any consent-valid activity
    • Under 10: Prohibited from providing personal data to social media platforms

    Full enforcement begins March 2026. This regulation affects any platform accessible to minors, which, in Indonesia’s mobile-first market, is nearly all of them.

    Our take: PP TUNAS will be the real compliance test. If platforms can’t implement unticked cookie consent boxes, a change that takes an afternoon, how are they going to implement age verification for users under 18? The same platforms that deploy pre-ticked consent boxes are now supposed to build parental consent flows, age-gating mechanisms, and data processing restrictions based on user age. This isn’t a regulation they can paper over with a privacy policy update. It requires actual engineering. And the platforms that haven’t started building will be exposed by March 2026.

    Permenkomdigi No. 5/2025: Data Localization

    Effective March 25, 2025, this regulation requires government-related data processing systems to prioritize local processing. Not technically a localization mandate, but it signals the direction of travel for data sovereignty requirements.

    Permenkomdigi No. 7/2026: Data Protection Compliance

    Published January 22, 2026, mandatory from July 1, 2026. This regulation formalizes DPIAs, breach notification requirements, and detailed processing principles. It’s the implementation regulation that turns UU PDP’s framework into specific compliance obligations.

    What Decision-Makers Should Do

    Five priorities based on what this assessment revealed.

    1. Fix Cookie Consent Now

    Six platforms deploy pre-ticked boxes. This is the single easiest compliance win. If your cookie banner uses pre-ticked opt-in boxes, replace them with unticked opt-in boxes. The technical change is trivial. The compliance risk of not doing it is significant; Article 22(1) is explicit.

    2. Build a Functional Erasure Process

    If your erasure process requires a 30-day verification cycle or government ID submission, you’re creating friction that will become enforcement liability. UU PDP requires erasure “without delay.” Build a process that’s auditable, documented, and actually works. One platform in our assessment proved this is possible.

    3. Audit What You Actually Share

    Most privacy policies describe data sharing in vague terms. Document every third party that receives personal data, every API endpoint that transmits it, and every analytics service that processes it. UU PDP Article 21 requires explicit consent for data sharing and allows data subjects to withdraw that consent. If you can’t answer “who has access,” you’re not compliant.

    4. Prepare for the DPA

    The regulator is coming. The Constitutional Court has ruled twice that the delay is unconstitutional. A draft Presidential Regulation is awaiting approval. When the DPA becomes operational, it will have authority to enforce fines, order data corrections, and pursue criminal charges. Treat UU PDP compliance as urgent now, not as a future obligation.

    5. Monitor Regulatory Updates

    The regulatory landscape is actively evolving. PP TUNAS full enforcement in March 2026, Permenkomdigi No. 7/2026 mandatory from July 2026, and potential data localization requirements signal the direction of travel. Subscribe to JDIH Kemkomdigi for official updates. The cost of non-compliance is rising.

    Methodology & Sources

    This analysis is based on a surface-level audit of 12 Indonesian platforms using publicly available information. No internal systems, processing records, or data subject request handling procedures were examined. The assessment relied on:

    • ABNR: Data Protection in Indonesia overview
    • AHP: Practical compliance guide
    • Cisometric: PDP vs GDPR comparison
    • CookieHub: Cookie consent compliance
    • hukumku.id: Right to erasure analysis
    • Prolegal: Cookie policy requirements, regulatory updates
    • PwC: PDP Insights 2025
    • RSM: Compliance preparation guide
    • SIP Law Firm: EU comparative analysis, cookie tracking legality, health data protection, erasure enforcement, cross-border transfers
    • Alta Advocates: PP TUNAS overview
    • PRIN: DPA deadlock analysis
    • ScholarHub: Government liability paper
    • Robere: PP TUNAS analysis
    • CyberStudio: 2024 breach cases
    • DLA Piper: Penalty structure
    • Alpha Code: Non-compliance penalties
    • CloudSEK: Telkom breach
    • CyberDefenseInsight: PLN breach
    • BBC Indonesia: BPJS Kesehatan breach
    • Rajah & Tann Asia: DPA establishment
    • WhoTracks.Me: Cookie consent data (2026)
    • TechSoup: Privacy Navigator compliance assessments
    • JDIH Kemkomdigi: UU PDP full text
    • APJII via Kompas: Internet penetration data

    The scoring methodology is a surface-level assessment, not a full regulatory audit. Actual compliance posture may differ from what public-facing elements suggest. Organizations should conduct their own detailed compliance assessments.

    The root-cause classification and compliance gap analysis are original analytical work based on this curated sample. The dataset is not a comprehensive registry. It is a structured sample designed to identify patterns in compliance posture across Indonesian platforms.


    Reference: UU PDP Compliance in Indonesia: Assessing the Paper-vs-Production Gap in Indonesia’s Post-Transition UU PDP Ecosystem by Adaptist Consulting.


    This research was conducted by Adaptist Consulting, July 2026. For questions about methodology or to discuss how these findings apply to your organization’s security posture, contact us.

    Profil Adaptist Consulting

    Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.