Sheila Thomas Law Office
Language
EN ID ZH
Search
Publications

Insights For Business Decisions

Practical perspectives on the legal and commercial decisions behind technology deployment, data use, distribution architectures, and cross-border transactions.

Indonesia's Data Protection Landscape in 2026: The DPA Is Coming, Enforcement Is Real, and Cross-Border Transfers Are Shifting
Legal Update • Aug 11, 2026

Indonesia's Data Protection Landscape in 2026: The DPA Is Coming, Enforcement Is Real, and Cross-Border Transfers Are Shifting

For nearly four years, Indonesia's Personal Data Protection Law (Law No. 27 of 2022, "PDP Law") has operated without the one institution its own text says must exist: a dedicated supervisory authority. That gap is now closing, and it is closing at the same time as three other developments are converging — a landmark trade agreement with the United States, a growing body of court decisions applying the PDP Law's criminal and civil provisions, and the early shape of Indonesia's AI governance framework. Together, these developments mark a genuine inflection point for any organization — local or foreign — that processes the personal data of individuals in Indonesia.This update walks through what has changed, what is about to change, and what businesses should be doing about it now.1. The Data Protection Authority Is Finally Taking ShapeArticle 58(5) of the PDP Law required the government to establish a dedicated supervisory authority — commonly referred to as the Lembaga PDP or Data Protection Authority (DPA) — through a Presidential Regulation. For years, this remained a promise on paper. In the meantime, supervisory functions have been carried out on a transitional basis by the Ministry of Communication and Digital Affairs ("MOCD," also referred to as Komdigi), specifically through its Directorate General of Digital Space Supervision, under MOCD Regulation No. 1 of 2025 on its organization and work procedures.That transitional arrangement is now approaching its end. A draft Presidential Regulation establishing the DPA was made public at the end of February 2026, nearly four years after the PDP Law was enacted, and has been submitted to the Ministry of State Secretariat pending presidential approval.Key structural features of the draft regulation include:The DPA will be a non-ministerial government agency reporting to the President through the MOCD, though the MOCD will not exercise operational supervisory authority over it.The DPA will be led by a Head appointed by the President, supported by three deputies responsible for policy and guidance, dispute resolution, and compliance and enforcement respectively.Its mandate, set out in Articles 3 and 4 of the draft regulation, covers policy formulation, regulatory oversight, administrative enforcement, out-of-court dispute resolution, and any additional functions the President assigns.Transitional provisions are designed to make the DPA operational immediately upon establishment, initially drawing on the personnel and resources of MOCD's existing personal data protection unit, which will eventually be absorbed into the new agency.Separately, the implementing regulation for the PDP Law itself — the long-awaited Draft Government Regulation on PDP Law ("Draft GR PDP") — has also progressed. As of late 2025, the Draft GR PDP had completed its harmonisation process and been passed to the State Secretary for approval by the President, although no firm timeline for finalisation has been confirmed.Why this matters: once the DPA is operational, enforcement of the PDP Law shifts from an ad hoc, transitional posture to a dedicated regulator with the institutional mandate to investigate, sanction, and mediate disputes. Businesses that have treated PDP Law compliance as a lower-priority item pending a "real" regulator should expect that grace period to end.2. Cross-Border Data Transfers to the United States: A New WrinkleIndonesia's PDP Law has always taken a cautious approach to cross-border data transfers. Article 56 requires data controllers to ensure that the destination jurisdiction offers a level of personal data protection equivalent to or higher than Indonesia's own, generally to be confirmed through an adequacy-style assessment once implementing regulations are in place.The U.S.–Indonesia Agreement on Reciprocal Trade, dated 19 February 2026, complicates — and potentially reshapes — this picture. Under Article 3.2 of Annex III of the Trade Agreement, Indonesia committed to providing legal certainty for personal data transfers to the United States by recognizing the U.S. as a jurisdiction offering adequate data protection under Indonesian law. In practical terms, this suggests an intent to treat U.S. data protection standards as equivalent to Indonesia's own — a significant commitment given how differently the two jurisdictions have historically approached privacy regulation.However, two important qualifications apply:The Trade Agreement is not yet self-executing under Indonesian law. Under Article 84 of Law No. 7 of 2004 on Trade, the agreement must first be submitted to the House of Representatives (DPR) for a ratification process, which will determine whether approval is required and whether ratification proceeds through a Law or a Presidential Regulation.The PDP Law's own adequacy mechanism has not been bypassed. The obligation under Article 56 of the PDP Law is expected to be discharged through a formal adequacy assessment and decision by the DPA — an assessment that a trade instrument, on its own, cannot substitute for. It remains unclear how the government will operationalise the U.S. commitment: whether through a formal DPA adequacy determination, amendments to implementing regulations, a dedicated assessment process, or some other mechanism.Why this matters: organizations that route personal data to U.S.-based affiliates, vendors, or cloud infrastructure should not yet assume that transfers to the U.S. are automatically compliant. Standard contractual safeguards, consent-based transfer mechanisms, or reliance on existing tiered-transfer options under the PDP Law remain the safer near-term approach until the adequacy question is formally resolved.3. The Courts Are Applying the PDP Law — and the Numbers Are No Longer SmallA common assumption in the early years of the PDP Law was that enforcement would remain largely theoretical until a dedicated regulator existed. Court activity since 2022 suggests otherwise. Since the PDP Law took effect in October 2022, a review of publicly available court registries and government directories identified at least 23 criminal cases, 7 civil cases, and 6 constitutional court decisions involving the PDP Law, a figure likely understated given that not all cases are yet published.Criminal CasesThree notable criminal cases were decided by district courts in 2025, involving the misuse of identity information to create Telegram accounts and monetise one-time passwords, unauthorised access to government systems to extract and sell employee data on the dark web, and the misuse of personal data to unlawfully reactivate a dormant account. Courts found the defendants guilty under Article 65(3) of the PDP Law for unlawful use of personal data and Article 65(1) for unlawful data collection for personal gain.Two practical observations follow: the criminal provisions of the PDP Law are now fully operational in practice, confirming genuine criminal exposure for unlawful data collection and misuse, though courts have so far tended to rely primarily on the Electronic Information and Transactions Law (UU ITE) as the primary legal basis, with the PDP Law functioning as a secondary or alternative basis — a reflection of how enforcement practice is still maturing.Civil CasesA notable civil claim was filed before the West Jakarta District Court in January 2026 by three former contract employees against their employer, alleging unlawful processing of personal data, including credit-history checks conducted without consent or contractual basis, alongside various labour law claims. While the case remains pending, it illustrates that employee background and credit checks carried out without a proper privacy notice and lawful basis can expose employers to tort-based civil liability, separate from any contractual dispute. For HR and compliance teams, this is a timely reminder that PDP Law exposure is not limited to customer-facing data processing.Constitutional Court DecisionsThree constitutional challenges to the PDP Law were filed and rejected in 2025. The rulings are worth noting individually:Cross-border transfers (Article 56): the Constitutional Court held that adequacy assessments fall within the government's executive-administrative authority and that the PDP Law's tiered cross-border transfer framework is constitutionally sound.Criminal liability carve-outs (Articles 65(2) and 67(2)): the Court found that journalistic, academic, and artistic activities are already adequately protected through existing sectoral laws and PDP Law exemptions, making additional express carve-outs unnecessary.Consent formalities (Article 20(2)(a)): a challenge arguing that consent should only be valid via certified electronic signatures was rejected as legally unreasonable, with the Court noting that such technical requirements are properly addressed through implementing regulations rather than constitutional interpretation.Why this matters: the PDP Law's cross-border transfer framework is now constitutionally settled, making further judicial challenge on that front unlikely, while the criminal liability regime for unlawful disclosure remains intact and interpreted alongside sectoral laws rather than through new express exemptions.4. AI Governance Is Catching Up — FastIndonesia has so far governed AI-adjacent activity through a patchwork of instruments: the Electronic Information and Transactions Law, Government Regulation No. 71 of 2019 on electronic systems, and the PDP Law itself. That patchwork is starting to consolidate.A Presidential Regulation on AI Ethics and Safety is expected in 2026, having been pushed back from an original 2025 target, and was reported to be roughly 90% complete as of late 2025 according to local media. This regulation is expected to introduce mandatory requirements for high-risk AI systems, including registration and impact-assessment obligations — a structure conceptually similar to the risk-tiered approach seen under the EU AI Act, though scaled to Indonesia's regulatory context.At the same time, financial sector regulation is moving in parallel: OJK guidance applies data reliability standards directly to AI-driven credit scoring and risk assessment, given the severe consequences flawed outputs can have for individuals and systemic stability, and separately requires financial institutions to ensure AI does not inadvertently exclude underserved populations from access to financial services, alongside explicit expectations of compliance with the PDP Law and strong cyber resilience.On the intellectual property side, a Draft Copyright Bill is expected to address AI-generated works, with industry observers anticipating a distinction between works autonomously generated by AI — which may fall outside copyright protection — and works produced with substantial human creative direction. Platforms hosting AI-generated content should begin preparing for new licensing and liability obligations that may follow from this distinction.Why this matters: organizations deploying AI systems that process personal data — which, in practice, is most AI systems handling Indonesian user data — should treat the PDP Law and the forthcoming AI Ethics and Safety regulation as complementary compliance tracks, not separate ones. A system that is PDP Law–compliant today may still need to satisfy new registration or impact-assessment obligations once the AI regulation takes effect.5. What This Means in PracticeTaken together, these developments point toward a regulatory environment that is becoming more institutionalized, more actively enforced, and more entangled with Indonesia's broader trade and technology policy. Organizations operating in or dealing with Indonesia — including foreign SaaS providers, cloud platforms, and AI developers whose services reach Indonesian users under the PDP Law's extraterritorial scope — should prioritize the following:Track the DPA's establishment closely. Once operational, it will be the body issuing implementing regulations, setting administrative fine levels, and handling complaints and enforcement — details that will materially affect compliance planning.Reassess cross-border transfer mechanisms, especially U.S.-linked flows. Do not treat the Trade Agreement's adequacy language as a compliance shortcut until ratification and DPA-level implementation are clarified. Maintain contractual safeguards and documented lawful bases for transfers in the meantime.Audit internal HR data processing. The West Jakarta civil case is a reminder that background checks, credit checks, and other employee-related processing require the same lawful-basis and notice rigor as customer-facing data processing.Review the lawful basis for every processing activity, ensure each processing purpose is necessary and consistent with actual business operations, and train personnel involved in data handling — the same practical steps regulators and courts are increasingly scrutinizing.Get ahead of AI-specific obligations. Where AI systems process personal data or make consequential decisions (credit, employment, access to services), begin preparing documentation, impact assessments, and governance structures now, ahead of the AI Ethics and Safety regulation's entry into force.Closing ThoughtsIndonesia's data protection framework is moving out of its transitional phase. A dedicated regulator is close to becoming a reality, courts are actively applying criminal and civil provisions, the Constitutional Court has closed off several avenues for challenging the law's core structure, and AI-specific regulation is arriving on a parallel track. For businesses that have been waiting for a "real" enforcement environment before investing seriously in PDP Law compliance, that wait is ending.This article is intended for general informational purposes only and does not constitute legal advice. Organizations should seek specific guidance tailored to their data processing activities and corporate structure.Sources: developments described above draw on publicly reported regulatory and court filings as of Q1–Q2 2026, including client updates from regional law firms, government directories, and industry commentary on Indonesia's PDP Law, the U.S.–Indonesia Agreement on Reciprocal Trade, and Indonesia's forthcoming AI Ethics and Safety regulation.

Read Article →
Stay Informed

Receive Legal & Market Updates

Subscribe to our brief, practical updates on changes in Indonesian regulation, cross-border compliance, and commercial law.

We respect your inbox. No spam, only critical updates.