When Indonesia's Personal Data Protection Law (UU PDP) was enacted in 2022, much of the commentary focused on its headline obligations: consent requirements, data subject rights, and breach notification within 72 hours. Two years on, with the transition period closed and the PDP supervisory authority operating under the Ministry of Communication and Digital Affairs, the practical enforcement picture has become clearer — and it looks different from what many businesses initially prepared for.
In practice, the authority's early enforcement activity has concentrated on data controllers that experienced reportable breaches without having documented a data protection impact assessment (DPIA) beforehand, and on entities transferring personal data cross-border without a legal basis on file. Fines and administrative sanctions to date have been calibrated to the sector and the harm involved, but the pattern is consistent: documentation is treated as evidence of a functioning compliance program, and its absence is treated as an aggravating factor.
For businesses that treated 2024's compliance deadline as a one-time project rather than an ongoing program, this is the moment to revisit the basics: an up-to-date data inventory, a designated data protection officer where the law requires one, and — critically — a written basis for every cross-border transfer of personal data currently in place.
We continue to advise clients across e-commerce, fintech, and healthcare on closing these gaps before they surface in a regulator's inquiry rather than in an internal audit.