Is Your Company Compliant with UU PDP? Current Status and Enforcement Reality

03 Jul 2026
by Guido van Beek, CTO & Co-founder
Editor: Nadiy, Senior Content Writer

03 Jul 2026
by Guido van Beek, CTO & Co-founder
Editor: Nadiy, Senior Content Writer
Is Your Company Compliant with UU PDP? Current Status and Enforcement Reality
Table of contents
Contact us
We will get back to you in the next 48 hours.

Indonesia's Personal Data Protection Law (UU PDP, Law No. 27 of 2022) became fully enforceable in October 2024. The transition period is over. The law applies now. And yet, most companies processing personal data in Indonesia have not done enough. Not because the law is unclear, but because enforcement so far has been inconsistent enough that the urgency has not felt real. That is starting to change.
key takeaways
The Law Is In Force. The Dedicated Agency Is Not Yet Operational.
The UU PDP mandated the President to establish a dedicated supervisory authority, the Lembaga PDP, to oversee and enforce the law. As of mid-2026, that agency still does not formally exist. A draft Presidential Regulation governing its structure and mandate entered harmonisation at the Ministry of Law in late 2025 and was submitted to the State Secretariat in February 2026, where it is currently awaiting presidential approval. The government has stated a target of 2026 for the Lembaga PDP to become operational, though this timeline has already shifted several times since 2022.
In the interim, enforcement authority sits with the Directorate General of Digital Space Supervision under Komdigi (the Ministry of Communication and Digital Affairs). This is explicitly a temporary arrangement. Komdigi has authority to monitor compliance, receive complaints from data subjects, coordinate with law enforcement on criminal matters, and impose administrative sanctions.
The absence of the Lembaga PDP does not mean the law is not being enforced.
It means enforcement is happening at a different level, with less consistency and public visibility than what will come once the dedicated agency is in place.
Enforcement is Already Happening
Between 2024 and mid-2025, Komdigi reviewed approximately 350 digital platforms. Potential violations were identified on 41% of websites and 34% of mobile applications reviewed. Through July 2025, Komdigi recorded 56 suspected UU PDP violation cases, with 20 cases identified in June 2025 alone.
These numbers are not widely publicised, and they have not yet resulted in the kind of high-profile enforcement actions that tend to change corporate behaviour quickly. But the direction is clear. Komdigi is building a body of cases. The Lembaga PDP, when it becomes operational, will inherit that work and have a formal mandate to act on it.
Companies that have treated the absence of visible enforcement as permission to delay are accumulating risk, not avoiding it.
What The Law Actually Requires
UU PDP establishes obligations that will be familiar to anyone who has worked with GDPR, though the implementing detail is still evolving. Nine implementing Government Regulations were mandated by the statute; as of mid-2026, none have received presidential signature.
The core obligations of the law itself, however, are clear and in force.
For any company running a digital platform that processes personal data of Indonesian users or citizens, the key requirements include: a documented legal basis for every category of personal data you collect, explicit consent mechanisms where consent is the basis, a breach notification obligation (72 hours to the supervisory authority, without unreasonable delay to affected individuals), data subject rights handling (access, correction, erasure), documented data retention and deletion protocols, and in many cases, appointment of a Data Protection Officer. Prioritizing robust security and ISO compliance within your architecture is essential to meeting these statutory requirements.
The penalties are not trivial. Administrative fines run up to 2% of annual revenue. Criminal sanctions apply for intentional unlawful processing, with legal entities facing up to 10 times the standard fine in aggravated cases.
What This Means For Companies Building Digital Products
If your platform processes personal data of Indonesian users, the compliance clock is not starting when the Lembaga PDP opens its doors. It started in October 2024.
The practical implication is that the compliance infrastructure needs to be in place before enforcement intensifies, not in response to it. That means documented data flows, a clear consent architecture, breach notification procedures that actually work, and a DPO or appointed compliance function if your processing scale requires it. For companies building or rebuilding digital products, the time to establish this foundation is during development, not after launch.
Retrofitting compliance into a live platform is significantly more expensive than building it in correctly from the start.
For Companies Working With External Software Partners
If you are working with a custom software development agency on a platform that will process personal data, your GDPR or UU PDP exposure does not end at your own organisation. It extends to how your software partners handle your data, what access controls they maintain, how they document changes to your production environment, and whether they can provide evidence of that to a regulator or auditor.
Most agencies cannot provide that evidence because they do not maintain it. We have written about how we structure this differently, and why compliance ended up becoming the backbone of our entire managed service model, in a previous blog here.
Where Things Are Likely To Go
The Lembaga PDP, once established, will have a formal mandate, dedicated staffing, and the authority to conduct its own investigations rather than relying on complaints or referrals. High-profile enforcement actions, sector-specific guidance, and clearer implementing regulations will follow.
Indonesia is not moving slowly on data protection because it does not care about it. It is moving slowly because the institutional machinery takes time to build. When it is built, enforcement will accelerate.
The window to get compliant without regulatory pressure is narrowing. The companies that act now will not be scrambling later.

If you want to future-proof your digital platform and align with strict global data standards, feel free to Contact Us to safeguard your software architecture today.

Indonesia's Personal Data Protection Law (UU PDP, Law No. 27 of 2022) became fully enforceable in October 2024. The transition period is over. The law applies now. And yet, most companies processing personal data in Indonesia have not done enough. Not because the law is unclear, but because enforcement so far has been inconsistent enough that the urgency has not felt real. That is starting to change.
The Law Is In Force. The Dedicated Agency Is Not Yet Operational.
The UU PDP mandated the President to establish a dedicated supervisory authority, the Lembaga PDP, to oversee and enforce the law. As of mid-2026, that agency still does not formally exist. A draft Presidential Regulation governing its structure and mandate entered harmonisation at the Ministry of Law in late 2025 and was submitted to the State Secretariat in February 2026, where it is currently awaiting presidential approval. The government has stated a target of 2026 for the Lembaga PDP to become operational, though this timeline has already shifted several times since 2022.
In the interim, enforcement authority sits with the Directorate General of Digital Space Supervision under Komdigi (the Ministry of Communication and Digital Affairs). This is explicitly a temporary arrangement. Komdigi has authority to monitor compliance, receive complaints from data subjects, coordinate with law enforcement on criminal matters, and impose administrative sanctions.
The absence of the Lembaga PDP does not mean the law is not being enforced.
It means enforcement is happening at a different level, with less consistency and public visibility than what will come once the dedicated agency is in place.
Enforcement is Already Happening
Between 2024 and mid-2025, Komdigi reviewed approximately 350 digital platforms. Potential violations were identified on 41% of websites and 34% of mobile applications reviewed. Through July 2025, Komdigi recorded 56 suspected UU PDP violation cases, with 20 cases identified in June 2025 alone.
These numbers are not widely publicised, and they have not yet resulted in the kind of high-profile enforcement actions that tend to change corporate behaviour quickly. But the direction is clear. Komdigi is building a body of cases. The Lembaga PDP, when it becomes operational, will inherit that work and have a formal mandate to act on it.
Companies that have treated the absence of visible enforcement as permission to delay are accumulating risk, not avoiding it.
What The Law Actually Requires
UU PDP establishes obligations that will be familiar to anyone who has worked with GDPR, though the implementing detail is still evolving. Nine implementing Government Regulations were mandated by the statute; as of mid-2026, none have received presidential signature.
The core obligations of the law itself, however, are clear and in force.
For any company running a digital platform that processes personal data of Indonesian users or citizens, the key requirements include: a documented legal basis for every category of personal data you collect, explicit consent mechanisms where consent is the basis, a breach notification obligation (72 hours to the supervisory authority, without unreasonable delay to affected individuals), data subject rights handling (access, correction, erasure), documented data retention and deletion protocols, and in many cases, appointment of a Data Protection Officer. Prioritizing robust security and ISO compliance within your architecture is essential to meeting these statutory requirements.
The penalties are not trivial. Administrative fines run up to 2% of annual revenue. Criminal sanctions apply for intentional unlawful processing, with legal entities facing up to 10 times the standard fine in aggravated cases.
What This Means For Companies Building Digital Products
If your platform processes personal data of Indonesian users, the compliance clock is not starting when the Lembaga PDP opens its doors. It started in October 2024.
The practical implication is that the compliance infrastructure needs to be in place before enforcement intensifies, not in response to it. That means documented data flows, a clear consent architecture, breach notification procedures that actually work, and a DPO or appointed compliance function if your processing scale requires it. For companies building or rebuilding digital products, the time to establish this foundation is during development, not after launch.
Retrofitting compliance into a live platform is significantly more expensive than building it in correctly from the start.
For Companies Working With External Software Partners
If you are working with a custom software development agency on a platform that will process personal data, your GDPR or UU PDP exposure does not end at your own organisation. It extends to how your software partners handle your data, what access controls they maintain, how they document changes to your production environment, and whether they can provide evidence of that to a regulator or auditor.
Most agencies cannot provide that evidence because they do not maintain it. We have written about how we structure this differently, and why compliance ended up becoming the backbone of our entire managed service model, in a previous blog here.
Where Things Are Likely To Go
The Lembaga PDP, once established, will have a formal mandate, dedicated staffing, and the authority to conduct its own investigations rather than relying on complaints or referrals. High-profile enforcement actions, sector-specific guidance, and clearer implementing regulations will follow.
Indonesia is not moving slowly on data protection because it does not care about it. It is moving slowly because the institutional machinery takes time to build. When it is built, enforcement will accelerate.
The window to get compliant without regulatory pressure is narrowing. The companies that act now will not be scrambling later.

If you want to future-proof your digital platform and align with strict global data standards, feel free to Contact Us to safeguard your software architecture today.
FAQs
The law has been in force since October 2024. If we haven't been fined yet, are we actually at risk?
We process data from both Indonesian and EU users. Do UU PDP and GDPR overlap, or do we need two separate compliance programs?
Do we need a Data Protection Officer under UU PDP?
Our software is built and maintained by an external agency. Are we still liable for how they handle our data?
What should we do first if we haven't started yet?
similar reads
Case Studies & Interviews
Lereng Tanah: Developing a Direct Booking Platform Malaysian Boutique Villa
29 January 2026
Case Studies & Interviews
Tactlink: How a Malaysian Entrepreneur Turned Networking Chaos into a Digital Community
22 January 2026
Case Studies & Interviews
PropTech Innovation: How Custom Software Development Transformed Homes In Asia
18 June 2026
Stuck between a great idea and the right team to build it?Let's talk.
We work with corporate innovation teams and ambitious scale-ups across the Netherlands, Singapore, and Australia, and wherever great software needs to be built. Drop us a message and we'll get back to you within one business day.


Markus Monnikendam
Global Commercial Director
hello@lizard.global