Indonesia’s Personal Data Protection Law (UU PDP) became fully enforceable on October 17, 2024, ending a two-year transition period. Nearly two years later, the supervisory authority the law mandates, the Lembaga PDP, still does not exist, and neither implementing regulation has been signed. Fines of up to 2% of annual revenue remain structurally unavailable, while Surfshark counts over 180 million compromised accounts tied to Indonesian data subjects.
We analyzed the primary text of UU 27/2022, every Constitutional Court challenge to it decided or pending through August 2026, the administrative history of the implementing regulations, and the enforcement actions Komdigi has taken under interim rules. The result is a compliance environment with no regional counterpart: the law is active, the regulator is absent, and the courts are quietly shaping what enforcement will eventually look like.
Summary
UU PDP was enacted on October 17, 2022, and Article 74 gave controllers and processors two years to comply. Full enforcement began on schedule, October 17, 2024. But Article 58, which establishes the Lembaga PDP, has never been activated. Interim enforcement sits with Komdigi’s Directorate General of Digital Space Supervision, acting on secondary instruments like Permenkominfo 5/2020, rules written before the PDP era.
The two regulations that would make the law operational are both stalled at the presidential desk. The RPerpres establishing the Lembaga PDP has been drafted since late 2022, received its presidential-initiative permission on March 4, 2025, completed inter-ministerial review, and was submitted to the President via a MenPAN-RB letter dated May 20, 2026, still unsigned as of August 19, 2026. The RPP PDP, which sets the fine procedures referenced in Article 57(5), completed its State Secretariat review in December 2025 and is also awaiting signature. UU PDP itself sets no statutory deadline for establishing the Lembaga, which is precisely why petitioners went to court.
This is a structural gap, not a scheduling problem. Article 57(3) authorizes administrative fines of up to 2% of annual revenue. Article 57(4) says those sanctions are imposed by the lembaga. Article 57(5) defers the procedure to a government regulation. None of the three prerequisites exists. Until the Lembaga PDP and the RPP PDP are both in place, the flagship penalty of Indonesia’s data protection regime cannot be issued.
The Regulatory Framework: UU PDP
UU PDP is a GDPR-modeled statute applying to every electronic system operator processing personal data in Indonesia, which includes virtually every e-commerce platform, fintech, telco, and government service.
| Article | Provision | What It Means in Practice |
|---|---|---|
| Article 4(2) | Defines sensitive (“specific”) personal data, including biometrics | Stricter processing conditions for health, biometric, and financial data |
| Articles 20–22 | Legal basis and consent | Consent must be explicit, informed, and purpose-bound; pre-ticked boxes are not valid |
| Article 12 | Right to sue for compensation | Data subjects can claim damages for unlawful processing |
| Article 46 | Breach notification | Notify affected subjects and the authority within 72 hours |
| Article 53 | Data Protection Officer (PPDP) appointment | Duty triggered by large-scale processing, and per MK 151, by any single statutory condition |
| Article 56 | Cross-border transfers | Three-layer mechanism: adequacy → appropriate safeguards → consent |
| Article 57 | Administrative sanctions | Fines up to 2% of annual revenue, but see the enforcement gap below |
| Articles 58–61 | Lembaga PDP | Establishment, functions, and authorities of the supervisory body |
| Article 62 | International cooperation | Cross-border data transfer agreements, upheld in MK 133 |
| Articles 65 & 67 | Unlawful disclosure | Criminal liability: up to 4 years’ imprisonment or a Rp 4 billion fine |
| Article 74 | Transition period | Two years from promulgation, the source of the October 2024 deadline |
The Enforcement Vacuum
The Lembaga PDP mandated by Article 58 is tasked with policy formulation, compliance supervision, administrative sanctioning, alternative dispute resolution, and cross-border transfer assessment. Its absence means the most consequential sanctions in the law are dormant.
| Instrument | Purpose | Status as of August 19, 2026 |
|---|---|---|
| RPerpres Badan PDP | Establishes the Lembaga PDP (Art 58) | Drafted since end-2022; izin prakarsa granted Mar 4, 2025; inter-ministerial review Mar–Sep 2025; harmonization from Oct 2025; public comment opened Feb 26, 2026 via pdp.id; submitted to the President via MenPAN-RB letter May 20, 2026, unsigned |
| RPP PDP | Implements fine procedures under Art 57(5) and operational rules | Drafting began 2023; harmonization Sep 2024–Aug 2025; request letter sent Oct 6, 2025; State Secretariat review completed Dec 2025, awaiting signature |
| Permenkominfo 5/2020 | Interim basis for PSE registration and sanctions | In force; used by Komdigi for the July 2026 PSE enforcement actions |
Komdigi’s Directorate General of Digital Space Supervision has been performing the Lembaga’s functions on an interim basis. But it does so with the tools of the old regime, notably Permenkominfo 5/2020 for PSE registration, and Article 40 of the ITE Law (as amended by UU 1/2024) for blocking. Article 40(2b) gives the government authority to order access termination for unlawful electronic information; Article 40A(5) lists the administrative sanctions available. None of this reaches the PDP Law’s own fine architecture.
The Courts Are Listening
The Constitutional Court has become the de facto referee of the PDP Law’s rollout. Six petitions have been decided and one remains live.
| Docket | Challenged Provision | Status |
|---|---|---|
| 151/PUU-XXII/2024 | Art 53(1)(b) | Granted (Jul 30, 2025): “dan” read as “dan/atau”, so any single condition triggers the PPDP appointment duty, the first judicial amendment of UU PDP |
| 135/PUU-XXIII/2025 | Arts 65(2) & 67(2) | Rejected (Jan 19, 2026): the unlawful-disclosure ban and its criminal sanction were upheld against journalists, academics, and artists |
| 137/PUU-XXIII/2025 | Art 56(1)–(4) | Rejected (Jan 19, 2026): cross-border adequacy is an executive/technical function, not a treaty requiring parliamentary approval |
| 133/PUU-XXIV/2026 | Art 62(2) | Rejected (May 25, 2026): reaffirmed the state’s constitutional duty to control cross-border transfers, with adequacy authority vested in the future Lembaga |
| 102/PUU-XXIV/2026 | Art 20(2)(f) “legitimate interest” | Not admissible (Apr 29, 2026) |
| 153/PUU-XXIV/2026 | Arts 58(5) & 61 | Not admissible (Jun 17, 2026); petitioners re-filed as 236 |
| 236/PUU-XXIV/2026 | Arts 58(5) & 61 | Pending: hearings Jul 27 and Aug 11, 2026; petition seeks a deadline to establish the Lembaga |
The 236 case is the one to watch. It directly targets the executive’s failure to establish the Lembaga PDP, invoking legal certainty (Art 28D(1)) and personal security rights (Art 28G(1)). If granted, it would impose a deadline on the President, the same effect the courts declined to reach in 153, which was dismissed on standing grounds.
The Breach Landscape
The enforcement vacuum has not been accompanied by a quiet threat environment.
| Year | Target | Scale | Status |
|---|---|---|---|
| 2020 | Tokopedia | ~91M accounts sold for ~US$5,000 | Verified |
| 2021 | BPJS Kesehatan | 279M records claimed by seller | Alleged/contested |
| 2021 | BRI Life | ~2M customer documents | Verified |
| 2022 | KPU | 105M voter records offered by Bjorka | Alleged/contested (KPU denied) |
| 2023 | BSI | ~1.5 TB / ~15M customers via LockBit | Verified (May 2023) |
| 2023 | Immigration | 34,900,867 passport records offered by Bjorka for US$10,000 | Alleged/contested (Imigrasi denied) |
| 2023 | Dukcapil | 337M records listed on BreachForums | Alleged/contested (Kemendagri denied) |
| 2023 | KPU DPT | 204.8M voter-roll records by “Jimbo” | Verified (Nov 2023) |
| 2024 | PDNS | ~282 state agencies; Brain Cipher ransomware | Verified |
| 2024 | DJP | ~6M NPWP records offered on BreachForums | Alleged/contested (DJP denied) |
| 2026 | Komdigi recruitment portal | Job-applicant CVs/KTPs exposed via a public Google Drive folder | Verified |
Surfshark’s longitudinal data tracks the trend: Indonesia ranked 3rd globally in Q3 2022 with 12.74 million compromised accounts, 13th over 2004–2024 with ~157 million records, and by Q2 2026 the running total exceeded 183 million. Quarterly counts remain elevated, roughly 944,000 in Q3 2025, 1.45–1.59 million in Q4 2025, and 912,589 in Q1 2026. A 2026 academic study separately counted 144, 176, and 198 recorded public-sector breach cases in 2023, 2024, and through October 2025, though this is a single-source estimate rather than an official government statistic. BSSN logged 4.41 billion traffic anomalies through September 2025, of which 93.8% were classified as malware.
What Enforcement Has Actually Happened
The absence of the Lembaga has not meant zero enforcement; it has meant enforcement through older, narrower tools.
July 2026: the PSE registration sweep. Komdigi notified 25 private-scope electronic system providers (15 foreign, 10 domestic, covering 57 websites and apps) on June 26, 2026 that they must register, citing Permenkominfo 5/2020 Articles 2 and 4. Three complied (AYO, Six Senses, Strava). The remaining 22 received written warnings around July 9–10 with a final July 13, 2026 deadline. As of August 19, 2026, no access blocking had been reported, but the mechanism, including blocking under Article 7 of the regulation, is live.
June 2025: the World platform suspension. On June 16, 2025, Komdigi upheld an indefinite operational suspension of the iris-scanning platform formerly known as Worldcoin, operating through Tools For Humanity and local partner PT Sandina Abadi Nusantara, which had collected iris scans from more than 500,000 Indonesian citizens in exchange for crypto tokens. The directives ordered permanent deletion of all iris codes, hashes, and encrypted copies, and required a governance overhaul guaranteeing zero children’s data. The case also settled the legal classification: biometrics are sensitive data under Article 4(2) of the PDP Law, not ordinary personal data.
Content blocking. In the first 100 days of the current government, Komdigi reported 1,037,558 items of negative content blocked (945,431 websites and 92,127 social media entries), using Article 40 UU ITE as amended by UU 1/2024.
Sectoral and investigative actions. In September 2024, Komdigi joined BSSN and the Police in the forensic investigation of the alleged 6-million-record DJP leak, and in April 2025 it enacted Permenkomdigi 7/2025, requiring identity verification for e-SIM issuance as a preemptive control against identity theft and SIM-swap fraud.
Child protection. PP 17/2025 (PP Tunas), governing PSEs’ child-protection obligations, took effect March 28, 2026, a reminder that sectoral obligations are moving forward even as the PDP Law’s own architecture stalls.
Our take: The dominant framing, “the law is active but nobody is enforcing it, so we have time”, is a misreading of the risk. The PSE sweep of July 2026 shows Komdigi will act through the instruments it has, and those instruments include access blocking. The fine that companies are betting on being unavailable is exactly what Article 57 will make available the day the RPP PDP and the Lembaga arrive. And the reputation damage from a breach does not wait for the regulator: 183 million compromised accounts, a 4.41-billion-anomaly year at BSSN, and a Constitutional Court that has already granted one petition and is weighing a deadline for the Lembaga’s creation. The vacuum is real. It is also temporary.
What You Should Do
Five priorities based on the enforcement landscape as of August 2026:
1. Appoint a Data Protection Officer now
Article 53 of UU PDP requires organizations processing data at scale to appoint a PPDP. MK 151 lowered the threshold: any single statutory condition now triggers the duty. The DPO appointment is cheap, visible, and is the single clearest signal of readiness when the Lembaga finally begins supervisory inspections.
2. Deploy granular consent management
Articles 20–22 require explicit, informed, unbundled consent for each distinct processing purpose. Most Indonesian operators still rely on bundled or implied consent. This is the most common gap found in compliance reviews, and it is the one regulators will test first because it is the easiest to audit.
3. Build a 72-hour breach-notification runbook
Article 46 requires notification of affected subjects and the authority within 72 hours of a breach. Without a tested runbook (incident classification, data inventory, legal review, notification templates), most organizations will miss the deadline in a real incident. The PDNS and World cases show the scrutiny a mishandled incident attracts.
4. Get your PSE registration right
The July 2026 sweep applied Permenkominfo 5/2020 registration obligations with hard deadlines and a blocking sanction in reserve. Registration status, completeness of data, and internal compliance functions under the regulation are now actively checked, not theoretical.
5. Review quarterly, using primary sources
The RPerpres and RPP PDP could be signed at any time, and MK 236 could impose a judicial deadline on the Lembaga’s creation. Subscribe to JDIH Kemkomdigi and the MKRI registry, and conduct quarterly reviews of retention schedules, vendor processing agreements, and third-party data flows. The legal references in your compliance documentation should already reflect the corrected provisions: Article 12 for compensation claims, Article 4(2) for biometrics, Article 74 for the transition period.
Methodology & Sources
This analysis is based on the primary text of UU 27/2022, UU 1/2024 (the ITE Law amendment), PP 17/2025, and Permenkominfo 5/2020 via JDIH; the Constitutional Court’s published decisions and registry data; and contemporaneous reporting on enforcement actions and breach incidents.
Key sources:
- JDIH (Kemkomdigi / Kemenkoinfra): primary text of UU 27/2022 (Arts 4(2), 12, 20–22, 46, 53, 56, 57, 58–61, 62, 65, 67, 74) and UU 1/2024 (Art 40(2b), Art 40A)
- MKRI: putusan and press materials for 151, 135, 137, 133, 102, 153, and 236/PUU
- Kompas, ANTARA, CNBC Indonesia, Tirto.id, Sindo News: RPerpres/RPP PDP status, MK hearings and verdicts, PSE sweep
- BBC Indonesia: Immigration 34M passport records claim (Jul 2023)
- BleepingComputer, Detik, IDN Times: Tokopedia, Dukcapil/KPU, DJP, Komdigi recruitment portal incidents
- Surfshark: Data Breach Statistics, Indonesia quarterly and cumulative figures
- BSSN: Cyber Threat Intelligence reports, traffic anomaly counts
- penerbitadm.pubmedia.id: 2026 academic study on public-sector breach case counts (single source)
- Hukumonline: BRI Life leak; PP 71/2019 lineage
Breach volumes attributed to named sellers are labeled as alleged/contested where the relevant institution publicly denied the data originated from its systems. Quarterly breach figures are point-in-time and subject to Surfshark’s periodic dataset revisions.
Reference: Two Years of Full Enforcement Without an Enforcer: A Tracking Study of UU PDP Implementation in Indonesia (2024–2026) by Adaptist Consulting.
Analysis conducted by Adaptist Consulting, August 2026. For questions about methodology or how these findings apply to your organization’s data governance infrastructure, contact us.
