Indonesia has a data protection law with real teeth and no dedicated jaw to bite with. Since 17 October 2024, Law No. 27 of 2022, the Undang-Undang Pelindungan Data Pribadi, has been fully enforceable. The two-year adjustment window in Article 74 expired that day. Every controller and processor handling Indonesian personal data is now, on paper, bound by the whole statute, and exposed to its top administrative fine of up to 2 percent of annual revenue.
Nearly two years later, the body meant to enforce all of it does not exist.
A penalty ceiling without a supervisor
The law wrote its own regulator into the text. It calls for an independent personal data protection authority, the Lembaga PDP, sitting directly under the President, with power to set policy, supervise controllers, investigate complaints, and impose sanctions. That authority was supposed to be created by presidential regulation. It has not been.
The implementing rules are stuck one draft short. The Government Regulation that fills in the operational detail, from cross-border transfer mechanics to the agency’s own structure, completed its inter-ministerial harmonisation around October 2025 and was passed to the State Secretary for the President to sign, according to Chambers’ 2026 Indonesia guide. There is no firm date. The government now targets 2026 to have the agency established and operational, a goal that has already slipped past the compliance deadline it was meant to precede.
So the sanctions are live and the enforcer is a draft. The gap is not academic. Article 57 lets the future authority fine a firm up to 2 percent of its annual revenue, order it to suspend processing, or force it to delete data. Those are the strongest instruments in the law. None of them has a standing owner.
Interim enforcement is a patchwork, not the authority the law wrote
Indonesia has not left the field entirely empty. Until the Lembaga PDP stands up, enforcement falls to whoever already holds a mandate. The Ministry of Communication and Digital, Komdigi, supervises electronic system operators through its digital-space oversight arm. The financial regulator OJK polices data handling inside financial services. The cyber agency BSSN owns incident response. DLA Piper’s country profile describes exactly this split.
That is not the same thing as a dedicated data protection authority, and the difference is the whole story. A sector regulator enforces data rules as a side duty, within its own perimeter, against firms it already licenses. It does not publish data-specific guidance, build a complaints pipeline for the general public, or set a national interpretation of consent, legitimate interest, or breach materiality. The two-year vacuum has produced almost none of the case-by-case doctrine that turns a statute into a predictable compliance target.
Compare the piece Clarqo ran on China this week. China stood up a working enforcement machine first, with the cyberspace regulator running graduated cross-border thresholds and a real review queue, then argued about how hard to turn the dial. Indonesia did the opposite. It set the penalty cliff, let the grace period run out, and left the lever unbuilt. One country has a regulator calibrating pressure. The other has a fine schedule waiting for someone authorised to use it.
What actually binds firms right now
The absent regulator changes the enforcement odds, not the obligations. Every substantive duty in the law is in force today for any firm processing Indonesian personal data.
Breach notification is the sharpest. Under Article 46, a controller must notify affected data subjects and the authority in writing within 72 hours of a personal data breach. The notice must state what data was exposed and how the controller is responding. The clock runs whether or not the recipient authority is fully constituted.
Appointment of a data protection officer is mandatory in the higher-risk cases set out in Article 53: processing for public services, large-scale systematic monitoring, or large-scale handling of sensitive or criminal-related data. Cross-border transfer sits under Articles 55 and 56, which require the destination country to offer protection at least equal to Indonesia’s, or binding safeguards, or the data subject’s consent. The operational detail of that transfer regime is one of the things still waiting on the unsigned Government Regulation, which leaves firms applying a principle without a rulebook.
Read together, the obligations are concrete and the supervision is thin. A company can be fully non-compliant with a live statute and face, in practice, a low probability of a formal sanction, because the office that would impose it is not yet open. That is a bad equilibrium. It trains firms to price compliance against enforcement odds rather than against the text, and it builds a backlog for the regulator that eventually arrives.
The reckoning is a standing-up, not a deadline
The usual framing for a data law is the compliance cliff: a date on the calendar after which the fines begin. Indonesia already passed that date in October 2024. The event that still matters is institutional, not chronological. It is the day the Lembaga PDP opens with a budget, an investigative staff, and a mandate that predates its own existence by two years.
When that happens, the grace period will be long gone. A firm that read the missing regulator as permission to defer its DPO appointment, its 72-hour breach playbook, or its transfer mapping will meet a new authority holding a two-year enforcement vacuum and every incentive to make early examples. The rational posture is to comply with the statute as written now, treating the interim patchwork and the absent agency as a timing question rather than a reprieve.
Indonesia proved a law can be fully enforceable and functionally unenforced at the same time. The 2 percent is real. The 72 hours are real. For now, the only thing missing is the institution the law itself demanded, and 2026 is the year it is supposed to arrive.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.