Indonesia’s E-Commerce Platforms Are Collecting Data Faster Than They Can Protect It

    August 12, 2026 / Published by: Admin

    Indonesia’s e-commerce market hit US$57.7 billion in GMV in 2025. The country has 229.4 million internet users at 80.66% penetration. But when we evaluated platform compliance against the country’s own Personal Data Protection Law, the results were stark: most platforms are technically secure but legally non-compliant, and the enforcement clock is already ticking.

    We analyzed cross-platform privacy compliance across Indonesia’s dominant e-commerce marketplaces, cross-referenced against breach data from Surfshark, network threat intelligence from BSSN (National Cyber and Crypto Agency), and the regulatory framework of UU PDP (Law No. 27 of 2022). The gap between data collection scale and governance readiness is the defining risk factor for Indonesia’s digital economy in 2026.

    Summary

    Indonesia enacted its Personal Data Protection Law (UU PDP) on October 17, 2022, with a two-year grace period that ended October 17, 2024. The law is now fully enforceable. Non-compliant entities face severe administrative sanctions, including corporate fines reaching up to 2% of annual revenue tied to the violation, temporary or permanent processing bans, mandatory data deletion orders, and criminal liability for deliberate illegal data harvesting or commercialization.

    Yet the enforcement body, the Lembaga PDP, has not been formally established as of August 2026. Interim enforcement is handled by the Ministry of Communication and Digital Affairs (Komdigi). This creates a paradox: the law is active, but the regulator is not.

    Meanwhile, Indonesia recorded 119.5 million compromised user accounts between 2020 and April 2026. The national cyber agency tracked 330.5 million network anomalies and 26.8 million phishing attacks in 2024 alone. The threat is not theoretical. It is structural.

    The Regulatory Framework: UU PDP

    UU PDP was modelled on the EU’s GDPR. It governs all Electronic System Providers (ESPs) operating in Indonesia, which includes every major e-commerce marketplace.

    RequirementUU PDPEU GDPRImpact on Platforms
    Enforcement StatusFully enforceable since Oct 17, 2024Since May 25, 2018Universal mandate for all platforms in Indonesia
    Maximum FinesUp to 2% of annual global turnoverUp to €20M or 4% of annual global turnoverSignificant financial exposure
    Supervisory BodyLembaga PDP (not yet established)National DPAsInterim enforcement by Komdigi
    DPO AppointmentRequired for large-scale processingRequired for large-scale monitoringOperational necessity for major platforms
    Cross-Border TransfersAdequacy, binding contract, or consentAdequacy decisions, SCCs, or BCRsRestructures regional cloud pipelines

    The Lembaga PDP, mandated under Article 58 of the PDP Law, is tasked with policy formulation, compliance supervision, administrative sanction enforcement, alternative dispute resolution, and cross-border data transfer assessments. Its pending establishment is the critical gap shaping corporate data privacy strategies through 2026.

    Marketplace Dynamics: Who Holds the Data

    Market concentration among a few dominant platforms determines the volume and complexity of consumer data processing.

    PlatformParent CompanyMarket Share (GMV)Monthly Web VisitsPrimary Data Focus
    Shopee IndonesiaSea Limited54.0%133.1MTransactional history, SeaMoney fintech, mobile telemetry
    TikTok Shop + TokopediaByteDance / GoTo Group38.0%65.2MVideo engagement, live-stream logs, checkout PII
    Lazada IndonesiaAlibaba Group6.0%32.4MLogistics tracking, cross-border trade, payment preferences
    BlibliPT Global Digital Niaga Tbk3.0%57.4MOmnichannel retail, first-party logistics, streaming logs

    In January 2024, TikTok completed its acquisition of a 75.01% controlling stake in Tokopedia for US$1.5 billion, following government regulations prohibiting direct e-commerce transactions on social media platforms. This merger unified social media engagement metrics, live-streaming behavioral tracking, and traditional checkout databases under a single operational infrastructure.

    Data compliance across these platforms is further complicated by deeply integrated third-party service providers. Marketplaces link user activity with payment gateways (such as QRIS, SeaMoney, and GoPay), third-party logistics networks, digital advertising engines, and micro-merchant fulfillment software. Consequently, regulatory oversight extends beyond customer-facing web interfaces to encompass backend API integrations and cloud infrastructure managing cross-border data flows.

    The Breach Landscape: 119.5 Million Accounts

    The necessity of enforcing UU PDP is reflected in the scale of data compromises.

    MetricVolumeContext
    Cumulative Breached Accounts (2020–2026)119,466,304~41 compromises per 100 citizens
    Peak Single-Quarter Breaches (Q2 2020)42,113,320Driven by Tokopedia breach (91M accounts)
    BSSN Phishing Attacks (2024)26,771,610Peak of 6.19M cases in December 2024
    BSSN Network Anomalies (2024)330,527,636Automated traffic anomalies across domestic networks
    Global Annual Breaches (2025)425,700,000~810 compromised accounts per minute worldwide

    The Tokopedia breach remains the defining incident: 91 million user and merchant account records stolen and offered for sale on dark web forums for US$5,000. The compromised data included full names, email addresses, phone numbers, birthdates, and hashed passwords.

    Subsequent breaches impacted Bukalapak (13 million records), BPJS Kesehatan (279 million records in 2021), Dukcapil (337 million records in 2023), and the Directorate General of Taxes (6 million NPWP records in 2024).

    Despite these historical vulnerabilities, longitudinal tracking reveals a stabilizing trend that correlates with the conclusion of the UU PDP transition period.

    Cross-Border Data and Customs Integration

    As e-commerce expands cross-border operations, privacy obligations intersect with customs data sharing requirements.

    Article 56 of the PDP Law establishes strict requirements for cross-border transfers. A data controller may transfer personal data internationally only if: (1) the destination jurisdiction has a data protection framework equal to or higher than UU PDP standards; (2) the data controller secures binding contractual data protection agreements with the foreign recipient; or (3) the data controller obtains explicit, informed consent from the data subject prior to the transfer.

    Under PMK 96/2023, Electronic Trading Platform Operators handling cross-border orders exceeding 1,000 transactions annually must integrate their systems with the Directorate General of Customs and Excise (DJBC).

    An empirical study of 178 platforms found:

    • System integration success rate: 89.6%
    • Platform compliance improvement: 64.7% to 92.4%
    • Cross-border trade value captured: 94.3%
    • Customs processing time reduction: from 12.3 days to 2.8 days
    • State import tax revenue increase: 65.1%

    This integration highlights the dual compliance demands: platforms must share transaction data with government databases under PMK 96/2023 while simultaneously enforcing end-to-end encryption and access controls under UU PDP.

    Our take: The Indonesian e-commerce sector faces a compliance paradox. The law is active, the threat landscape is escalating, and the regulator doesn’t exist yet. Companies that treat UU PDP compliance as a future problem, waiting for the Lembaga PDP to begin issuing penalties, are making a bet that the regulator will be slow. That bet may be correct in the short term, but the reputational damage from a breach doesn’t wait for regulatory action. The 119.5 million compromised accounts aren’t hypothetical. They’re real users whose data is circulating on dark web forums right now. Every month the Lembaga PDP remains unestablished is a month where enforcement uncertainty grows, and so does the pile of unaddressed compliance gaps.

    What You Should Do

    Five priorities based on the compliance landscape:

    1. Deploy Granular Consent Management

    Replace passive or bundled consent banners with explicit, opt-in Consent Management Platforms (CMPs). UU PDP Articles 20–22 require unbundled, non-pre-ticked consent for distinct processing purposes. Most platforms still use bundled or implied consent. This is the single most common compliance gap.

    2. Map Your Data End-to-End

    Deploy automated data discovery tools to catalog PII across cloud databases, payment gateways, and third-party logistics networks. Categorize data into general and sensitive personal data per UU PDP standards. Enforce AES-256 encryption at rest and TLS 1.3 in transit.

    3. Execute Vendor Data Transfer Agreements

    Every third-party processor, including logistics providers, payment gateways, and analytics tools, needs a formal Data Transfer Agreement. These must establish processing parameters, mandate 72-hour breach notification, require data deletion on contract termination, and preserve audit rights.

    4. Appoint a DPO

    Article 53 of UU PDP requires organizations processing data at scale to appoint a Data Protection Officer. The DPO must report directly to executive leadership and perform formal Data Protection Impact Assessments before launching new features or cross-border data flows.

    5. Prepare for the Lembaga PDP

    The Lembaga PDP is coming. Treat UU PDP compliance as urgent now, not as a future checkbox. Subscribe to JDIH Kemkomdigi for official regulatory updates. Conduct quarterly reviews of data retention schedules, vendor processing agreements, and third-party data flows.

    Implementation Phases

    PhaseFocus AreaPrimary DeliverablesStatutory Mandates
    Phase 1: Immediate (Months 1–3)Consent & GovernanceDeploy granular opt-in CMPs; eliminate pre-ticked boxesUU PDP Articles 20–22
    Phase 2: Short-Term (Months 3–6)Data Mapping & DPOComplete PII mapping; appoint DPO; execute vendor DTAsUU PDP Articles 53–54
    Phase 3: Medium-Term (Months 6–12)Cross-Border & StorageDeploy data retention/deletion workflows; establish BCRsUU PDP Article 56
    Phase 4: Long-Term (Continuous)Audit & MonitoringBiannual DPIAs; penetration testing; BSSN threat feedsLembaga PDP Framework

    Regulatory Recommendations

    The Lembaga PDP should prioritize issuing definitive technical guidelines regarding cross-border data transfer mechanisms, including standardized contractual clauses (SCCs) and formal adequacy determinations for key trade partner jurisdictions. Additionally, recognizing that micro, small, and medium enterprises (MSMEs) face resource constraints, regulators should establish simplified privacy toolkits tailored for MSMEs to raise merchant-level compliance and prevent vendor-side data leaks.

    Methodology & Sources

    This analysis synthesizes cross-platform compliance assessments, longitudinal breach monitoring data from Surfshark, network threat intelligence from BSSN, and the regulatory framework of Indonesia’s UU PDP and PMK 96/2023.

    Key sources:

    • Momentum Works: Indonesia E-Commerce Market Report 2025, US$57.7B GMV, market share distribution
    • Mordor Intelligence: SEA Cross-Border E-Commerce Market, US$45.39B (2025), 10.97% CAGR through 2031
    • Surfshark: Data Breach Monitor, 119.5M cumulative compromised accounts (2020–Apr 2026)
    • BSSN (Badan Siber dan Sandi Negara): Cyber Threat Intelligence Report 2024, 330.5M anomalies, 26.8M phishing attacks
    • APJII (Asosiasi Penyelenggara Jasa Internet Indonesia): Internet Users Survey 2025, 229.4M users, 80.66% penetration
    • Semrush: Web Traffic Analysis July 2025, Shopee 133.1M, Tokopedia 65.2M, Blibli 57.4M, Lazada 32.4M monthly visits
    • Frisca & Tirtakusuma (2025): Analysis of Implementation of PMK 96/2023, 178 platforms, integration metrics
    • DLA Piper: Data Protection Laws and Regulations, Indonesia Lembaga PDP status (pending establishment)
    • YAPLegal: UU PDP Compliance Obligations, Article references, penalties, DPO requirements
    • Taalenta: One Year of UU PDP Full Enforcement, Enforcement gaps and breach patterns

    Market share data, breach volumes, and regulatory references are drawn from publicly available reports. The PMK 96/2023 implementation metrics are derived from an empirical study of 178 e-commerce platforms and 87 customs officials.


    Reference: Cross-Platform Data Governance and Regulatory Compliance Benchmark in Southeast Asian E-Commerce by Adaptist Consulting.


    Analysis conducted by Adaptist Consulting, August 2026. For questions about methodology or how these findings apply to your organization’s data governance infrastructure, contact us.

    Profil Adaptist Consulting

    Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.