Indonesia’s e-commerce market hit US$57.7 billion in GMV in 2025. The country has 229.4 million internet users at 80.66% penetration. But when we evaluated platform compliance against the country’s own Personal Data Protection Law, the results were stark: most platforms are technically secure but legally non-compliant, and the enforcement clock is already ticking.
We analyzed cross-platform privacy compliance across Indonesia’s dominant e-commerce marketplaces, cross-referenced against breach data from Surfshark, network threat intelligence from BSSN (National Cyber and Crypto Agency), and the regulatory framework of UU PDP (Law No. 27 of 2022). The gap between data collection scale and governance readiness is the defining risk factor for Indonesia’s digital economy in 2026.
Summary
Indonesia enacted its Personal Data Protection Law (UU PDP) on October 17, 2022, with a two-year grace period that ended October 17, 2024. The law is now fully enforceable. Non-compliant entities face severe administrative sanctions, including corporate fines reaching up to 2% of annual revenue tied to the violation, temporary or permanent processing bans, mandatory data deletion orders, and criminal liability for deliberate illegal data harvesting or commercialization.
Yet the enforcement body, the Lembaga PDP, has not been formally established as of August 2026. Interim enforcement is handled by the Ministry of Communication and Digital Affairs (Komdigi). This creates a paradox: the law is active, but the regulator is not.
Meanwhile, Indonesia recorded 119.5 million compromised user accounts between 2020 and April 2026. The national cyber agency tracked 330.5 million network anomalies and 26.8 million phishing attacks in 2024 alone. The threat is not theoretical. It is structural.
The Regulatory Framework: UU PDP
UU PDP was modelled on the EU’s GDPR. It governs all Electronic System Providers (ESPs) operating in Indonesia, which includes every major e-commerce marketplace.
| Requirement | UU PDP | EU GDPR | Impact on Platforms |
|---|---|---|---|
| Enforcement Status | Fully enforceable since Oct 17, 2024 | Since May 25, 2018 | Universal mandate for all platforms in Indonesia |
| Maximum Fines | Up to 2% of annual global turnover | Up to €20M or 4% of annual global turnover | Significant financial exposure |
| Supervisory Body | Lembaga PDP (not yet established) | National DPAs | Interim enforcement by Komdigi |
| DPO Appointment | Required for large-scale processing | Required for large-scale monitoring | Operational necessity for major platforms |
| Cross-Border Transfers | Adequacy, binding contract, or consent | Adequacy decisions, SCCs, or BCRs | Restructures regional cloud pipelines |
The Lembaga PDP, mandated under Article 58 of the PDP Law, is tasked with policy formulation, compliance supervision, administrative sanction enforcement, alternative dispute resolution, and cross-border data transfer assessments. Its pending establishment is the critical gap shaping corporate data privacy strategies through 2026.
Marketplace Dynamics: Who Holds the Data
Market concentration among a few dominant platforms determines the volume and complexity of consumer data processing.
| Platform | Parent Company | Market Share (GMV) | Monthly Web Visits | Primary Data Focus |
|---|---|---|---|---|
| Shopee Indonesia | Sea Limited | 54.0% | 133.1M | Transactional history, SeaMoney fintech, mobile telemetry |
| TikTok Shop + Tokopedia | ByteDance / GoTo Group | 38.0% | 65.2M | Video engagement, live-stream logs, checkout PII |
| Lazada Indonesia | Alibaba Group | 6.0% | 32.4M | Logistics tracking, cross-border trade, payment preferences |
| Blibli | PT Global Digital Niaga Tbk | 3.0% | 57.4M | Omnichannel retail, first-party logistics, streaming logs |
In January 2024, TikTok completed its acquisition of a 75.01% controlling stake in Tokopedia for US$1.5 billion, following government regulations prohibiting direct e-commerce transactions on social media platforms. This merger unified social media engagement metrics, live-streaming behavioral tracking, and traditional checkout databases under a single operational infrastructure.
Data compliance across these platforms is further complicated by deeply integrated third-party service providers. Marketplaces link user activity with payment gateways (such as QRIS, SeaMoney, and GoPay), third-party logistics networks, digital advertising engines, and micro-merchant fulfillment software. Consequently, regulatory oversight extends beyond customer-facing web interfaces to encompass backend API integrations and cloud infrastructure managing cross-border data flows.
The Breach Landscape: 119.5 Million Accounts
The necessity of enforcing UU PDP is reflected in the scale of data compromises.
| Metric | Volume | Context |
|---|---|---|
| Cumulative Breached Accounts (2020–2026) | 119,466,304 | ~41 compromises per 100 citizens |
| Peak Single-Quarter Breaches (Q2 2020) | 42,113,320 | Driven by Tokopedia breach (91M accounts) |
| BSSN Phishing Attacks (2024) | 26,771,610 | Peak of 6.19M cases in December 2024 |
| BSSN Network Anomalies (2024) | 330,527,636 | Automated traffic anomalies across domestic networks |
| Global Annual Breaches (2025) | 425,700,000 | ~810 compromised accounts per minute worldwide |
The Tokopedia breach remains the defining incident: 91 million user and merchant account records stolen and offered for sale on dark web forums for US$5,000. The compromised data included full names, email addresses, phone numbers, birthdates, and hashed passwords.
Subsequent breaches impacted Bukalapak (13 million records), BPJS Kesehatan (279 million records in 2021), Dukcapil (337 million records in 2023), and the Directorate General of Taxes (6 million NPWP records in 2024).
Despite these historical vulnerabilities, longitudinal tracking reveals a stabilizing trend that correlates with the conclusion of the UU PDP transition period.
Cross-Border Data and Customs Integration
As e-commerce expands cross-border operations, privacy obligations intersect with customs data sharing requirements.
Article 56 of the PDP Law establishes strict requirements for cross-border transfers. A data controller may transfer personal data internationally only if: (1) the destination jurisdiction has a data protection framework equal to or higher than UU PDP standards; (2) the data controller secures binding contractual data protection agreements with the foreign recipient; or (3) the data controller obtains explicit, informed consent from the data subject prior to the transfer.
Under PMK 96/2023, Electronic Trading Platform Operators handling cross-border orders exceeding 1,000 transactions annually must integrate their systems with the Directorate General of Customs and Excise (DJBC).
An empirical study of 178 platforms found:
- System integration success rate: 89.6%
- Platform compliance improvement: 64.7% to 92.4%
- Cross-border trade value captured: 94.3%
- Customs processing time reduction: from 12.3 days to 2.8 days
- State import tax revenue increase: 65.1%
This integration highlights the dual compliance demands: platforms must share transaction data with government databases under PMK 96/2023 while simultaneously enforcing end-to-end encryption and access controls under UU PDP.
Our take: The Indonesian e-commerce sector faces a compliance paradox. The law is active, the threat landscape is escalating, and the regulator doesn’t exist yet. Companies that treat UU PDP compliance as a future problem, waiting for the Lembaga PDP to begin issuing penalties, are making a bet that the regulator will be slow. That bet may be correct in the short term, but the reputational damage from a breach doesn’t wait for regulatory action. The 119.5 million compromised accounts aren’t hypothetical. They’re real users whose data is circulating on dark web forums right now. Every month the Lembaga PDP remains unestablished is a month where enforcement uncertainty grows, and so does the pile of unaddressed compliance gaps.
What You Should Do
Five priorities based on the compliance landscape:
1. Deploy Granular Consent Management
Replace passive or bundled consent banners with explicit, opt-in Consent Management Platforms (CMPs). UU PDP Articles 20–22 require unbundled, non-pre-ticked consent for distinct processing purposes. Most platforms still use bundled or implied consent. This is the single most common compliance gap.
2. Map Your Data End-to-End
Deploy automated data discovery tools to catalog PII across cloud databases, payment gateways, and third-party logistics networks. Categorize data into general and sensitive personal data per UU PDP standards. Enforce AES-256 encryption at rest and TLS 1.3 in transit.
3. Execute Vendor Data Transfer Agreements
Every third-party processor, including logistics providers, payment gateways, and analytics tools, needs a formal Data Transfer Agreement. These must establish processing parameters, mandate 72-hour breach notification, require data deletion on contract termination, and preserve audit rights.
4. Appoint a DPO
Article 53 of UU PDP requires organizations processing data at scale to appoint a Data Protection Officer. The DPO must report directly to executive leadership and perform formal Data Protection Impact Assessments before launching new features or cross-border data flows.
5. Prepare for the Lembaga PDP
The Lembaga PDP is coming. Treat UU PDP compliance as urgent now, not as a future checkbox. Subscribe to JDIH Kemkomdigi for official regulatory updates. Conduct quarterly reviews of data retention schedules, vendor processing agreements, and third-party data flows.
Implementation Phases
| Phase | Focus Area | Primary Deliverables | Statutory Mandates |
|---|---|---|---|
| Phase 1: Immediate (Months 1–3) | Consent & Governance | Deploy granular opt-in CMPs; eliminate pre-ticked boxes | UU PDP Articles 20–22 |
| Phase 2: Short-Term (Months 3–6) | Data Mapping & DPO | Complete PII mapping; appoint DPO; execute vendor DTAs | UU PDP Articles 53–54 |
| Phase 3: Medium-Term (Months 6–12) | Cross-Border & Storage | Deploy data retention/deletion workflows; establish BCRs | UU PDP Article 56 |
| Phase 4: Long-Term (Continuous) | Audit & Monitoring | Biannual DPIAs; penetration testing; BSSN threat feeds | Lembaga PDP Framework |
Regulatory Recommendations
The Lembaga PDP should prioritize issuing definitive technical guidelines regarding cross-border data transfer mechanisms, including standardized contractual clauses (SCCs) and formal adequacy determinations for key trade partner jurisdictions. Additionally, recognizing that micro, small, and medium enterprises (MSMEs) face resource constraints, regulators should establish simplified privacy toolkits tailored for MSMEs to raise merchant-level compliance and prevent vendor-side data leaks.
Methodology & Sources
This analysis synthesizes cross-platform compliance assessments, longitudinal breach monitoring data from Surfshark, network threat intelligence from BSSN, and the regulatory framework of Indonesia’s UU PDP and PMK 96/2023.
Key sources:
- Momentum Works: Indonesia E-Commerce Market Report 2025, US$57.7B GMV, market share distribution
- Mordor Intelligence: SEA Cross-Border E-Commerce Market, US$45.39B (2025), 10.97% CAGR through 2031
- Surfshark: Data Breach Monitor, 119.5M cumulative compromised accounts (2020–Apr 2026)
- BSSN (Badan Siber dan Sandi Negara): Cyber Threat Intelligence Report 2024, 330.5M anomalies, 26.8M phishing attacks
- APJII (Asosiasi Penyelenggara Jasa Internet Indonesia): Internet Users Survey 2025, 229.4M users, 80.66% penetration
- Semrush: Web Traffic Analysis July 2025, Shopee 133.1M, Tokopedia 65.2M, Blibli 57.4M, Lazada 32.4M monthly visits
- Frisca & Tirtakusuma (2025): Analysis of Implementation of PMK 96/2023, 178 platforms, integration metrics
- DLA Piper: Data Protection Laws and Regulations, Indonesia Lembaga PDP status (pending establishment)
- YAPLegal: UU PDP Compliance Obligations, Article references, penalties, DPO requirements
- Taalenta: One Year of UU PDP Full Enforcement, Enforcement gaps and breach patterns
Market share data, breach volumes, and regulatory references are drawn from publicly available reports. The PMK 96/2023 implementation metrics are derived from an empirical study of 178 e-commerce platforms and 87 customs officials.
Reference: Cross-Platform Data Governance and Regulatory Compliance Benchmark in Southeast Asian E-Commerce by Adaptist Consulting.
Analysis conducted by Adaptist Consulting, August 2026. For questions about methodology or how these findings apply to your organization’s data governance infrastructure, contact us.
