Database

Browse Database

INDONESIA

Since April 2008, entry into force in April 2010, as amended in November 2016, last amended in January 2024

Pillar Content access  |  Indicator Blocking or filtering of commercial web content
Law No. 11 on Electronic Information and Transactions (Undang-undang (UU) Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik)
Art. 40 of the Law on Electronic Information and Transactions confers upon the government the authority to terminate access to electronic information and/or electronic documents, or to instruct electronic system operators to do so, where such material contains unlawful content. Any such instruction addressed to an electronic system operator may take the form of access termination and/or independent content moderation in respect of electronic information and/or electronic documents containing pornographic material, gambling-related content, or other forms of content as stipulated under the applicable laws and regulations, insofar as such measures are technologically feasible. In addition, the government is empowered to require electronic system operators to undertake content moderation of electronic information and/or electronic documents that are deemed harmful to the safety of life or to the health of individuals or the public at large.
It is reported that, in May 2025, the authorities briefly blocked access to the digital library Archive.org. This temporary restriction formed part of the government’s enforcement actions in response to potential copyright infringements and the identification of content alleged to contravene the Law on Electronic Information and Transactions.
Coverage Digital library Archive.org

INDONESIA

Since November 2019

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Government Regulation of the Republic of Indonesia No. 80 of 2019 on Trading Through Electronic Systems (Peraturan Pemerintah Republik Indonesia Nomor 80 Tahun 2019 Tentang Perdagangan Melalui Sistem Elektronik)
Art. 59 of the Government Regulation No. 80/2019 states that personal data collected in e-commerce activities cannot be sent overseas unless the relevant Ministries confirm that the foreign country has the same level of personal data protection standard as Indonesia.
Coverage E-commerce activities

INDONESIA

Since December 2016

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Regulation of Minister of Communication and Informatics No. 20 of 2016 on Personal Data Protection in Electronic Systems (Peraturan Menteri Komunikasi dan Informatika Nomor 20 Tahun 2016 tentang Perlindungan Data Pribadi Dalam Sistem Elektronik)
Pursuant to Arts. 1, 3, and 6 of the "Regulation of the Minister of Communication and Informatics No. 20 of 2016 on Personal Data Protection in Electronic Systems", electronic system operators are required to obtain the consent of data subjects prior to any cross-border transfer of personal data. Such consent must be provided either in Bahasa Indonesia or in a bilingual format and may be obtained either electronically or in hard copy.
For the purposes of this regulation, an electronic system operator is defined as any individual, state authority, business entity, or community group that provides, manages, and/or operates electronic systems, either independently or jointly, for the benefit of users of electronic systems, whether for their own purposes or on behalf of third parties.
Coverage Electronic system operators

INDONESIA

Signed in March 2019, entry into force in July 2020

Pillar Cross-border data policies  |  Indicator Participation in trade agreements committing to open cross-border data flows
Indonesia - Australia Comprehensive Economic Partnership Agreement
Indonesia has joined an agreement with binding commitments to open transfers of data across borders: Indonesia - Australia Comprehensive Economic Partnership Agreement (Art. 13.11).
Coverage Horizontal

INDONESIA

Since September 2022, entry into force in October 2022

Pillar Domestic data policies  |  Indicator Framework for data protection
Law No. 27 of 2022 on Personal Data Protection (Undang-undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi)
The Law on Personal Data Protection provides a comprehensive regime of data protection in Indonesia.
Coverage Horizontal

INDONESIA

Since December 2016
Since September 2022, entry into force in October 2022

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Regulation of the Minister of Communication and Information Technology No. 20 of 2016 on Protection of Personal Data in Electronic Systems (Peraturan Menteri Komunikasi dan Informatika Nomor 20 Tahun 2016 Tentang Perlindungan Data Pribadi Dalam Sistem Elektronik)

Law No. 27 of 2022 on Personal Data Protection (Undang-undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi)
The Minister of Communication and Informatics Regulation No. 20 of 2016 mandates the minimum retention for stored personal data at five years (unless stated otherwise in other laws and regulations). An exemption to this provision is stipulated under Art. 16 of Law No. 27, where personal data must be destroyed and/or deleted after the expiry of the retention period or at the request of the data subject.
Coverage Electronic systems operators

INDONESIA

Since November 2019

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Government Regulation of the Republic of Indonesia No. 80 of 2019 on Trading Through Electronic Systems (Peraturan Pemerintah Republik Indonesia Nomor 80 Tahun 2019 Tentang Perdagangan Melalui Sistem Elektronik)
Government Regulation No. 80/2019 states that domestic or foreign e-commerce platforms that operate in Indonesia should store data for at least 10 years for financial transactions and 5 years for non-financial transactions since the data were collected.
Coverage E-commerce platforms

INDONESIA

Reported in 2017, last reported in 2025

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Lack of an independent telecom authority
It is reported that Indonesia lacks a telecommunications authority whose decision-making process is independent of the government. In general, matters relating to telecommunications are regulated and supervised by the Ministry of Communication and Digital.
Coverage Telecommunications sector

INDONESIA

Since July 2022, entry into force in October 2022
Since December 2016, last amended in March 2020, until October 2022

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
OJK Regulation (POJK) No. 11/POJK.03/2022 on the Implementation of Information Technology by Commercial Banks (Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 Tahun 2022 tentang Penyelenggaraan Teknologi Informasi Oleh Bank Umum)

POJK No. 38/POJK.03/2016 on the Implementation of Risk Management in the Use of Information Technology by Commercial Banks (Peraturan Otoritas Jasa Keuangan Nomor 38/POJK.03/2016 Tahun 2016 tentang Penerapan Manajemen Risiko Dalam Penggunaan Teknologi Informasi oleh Bank Umum)
In accordance with Art. 35 of OJK Regulation (POJK) No. 11/POJK.03/2022, banks are required to place their electronic systems in data centres and disaster recovery centres in Indonesia. Yet, banks may place them outside Indonesia upon obtaining authorisation from the Financial Services Authority (OJK). According to Art. 36, banks may apply for an authorisation provided that they:
- meet the regulatory provisions on the use of IT service providers in IT implementation;
- submit the results of the country risk analysis;
- ensure that the placement of the electronic systems in data centres and/or disaster recovery centres outside Indonesia does not diminish the effectiveness of OJK’s supervision as demonstrated by a statement letter;
- ensure that information regarding the bank’s confidentiality is only disclosed on the condition that such disclosure complies with the provisions of the statutory regulations in Indonesia, as evidenced by the cooperation agreement between the bank and the IT service provider;
- ensure that the written agreement with the IT service provider contains a choice of law clause;
- submit a no-objection letter from the supervisory authority of the IT service provider outside Indonesia so that OJK can conduct inspections on the IT service provider;
- submit a statement letter that the bank shall periodically submit the results of assessments conducted by the bank office(s) outside Indonesia on the application of risk management on the IT service provider;
- ensure that the placement plan of the electronic systems in data centres and/or disaster recovery centres outside Indonesia delivers more benefits than the costs for the bank; and
- submit the bank's plan to improve the bank's human resources capacity, both in IT implementation and in business transactions or products offered.
In addition, according to Art. 39, banks are required to process IT-based transactions within the Indonesian territory. However, the processing of IT-based transactions by the IT service providers outside Indonesia can be carried out provided that the bank has obtained authorisation from OJK. Banks may apply for an authorisation on the condition that:
- IT service providers comply with the prudential principle, with the regulatory provisions on the IT service providers in IT implementation, and take heed of consumer protection.
- the supporting documents for financial administration for transactions conducted at the bank offices in Indonesia are administered at the bank offices in Indonesia; and
- the bank's business plan demonstrates efforts to increase its role in developing Indonesia’s economy.
OJK Regulation (POJK) No. 11/POJK.03/2022 revoked and declared null and void OJK Regulation (POJK) No. 38/POJK.03/2016, which already required foreign banks and payments networks to locate data centres and process electronic transactions in Indonesia.
Coverage Financial sector

INDONESIA

Since December 2020

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Bank Indonesia Regulation No. 22/23/PBI/2020 on Payment Systems (Peraturan Bank Indonesia Nomor 22/23/PBI/2020 Tentang Sistem Pembayaran)
Art. 35 of Bank Indonesia Regulation No. 22/23/PBI/2020 requires domestic processing of initiation-authorisation-clearing-settlements phases of payment transactions for instruments issued by Indonesia's payment service provider and conducted within the territory of the Republic of Indonesia. Indonesia opens the possibility of such payment transactions being processed outside of Indonesian territory for the purpose of global reconciliation, integrated risk management system, and anti-money laundering. However, this is subject to Bank Indonesia's approval.
Coverage Financial sector

INDONESIA

Since October 2019
Since October 2012 until October 2019

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Regulation of the Government of the Republic of Indonesia No. 71 of 2019 on Electronic System and Transaction Operations (Peraturan Pemerintah Republik Indonesia Nomor 71 Tahun 2019 Tentang Penyelenggaraan Sistem Dan Transaksi Elektronik)

Government Regulation No. 82 of 2012 on Electronic System and Transaction Operations (Peraturan Pemerintah (PP) Nomor 82 Tahun 2012 tentang Penyelenggaraan Sistem Dan Transaksi Elektronik)
Art. 20 of Regulation No. 71 provides that public electronic system operators (ESOs) are required to manage, process, and/or store electronic systems and electronic data in the territory of Indonesia, except if the technology is not yet available. Private ESOs can manage, process, and/or store electronic systems and electronic data in Indonesia and/or outside the country (Art. 21). However if management is carried out outside, it must ensure the effectiveness of supervision by the ministry.
Art. 1 contains several key definitions:
- Electronic system: a set of electronic equipment and procedures that have the function of preparing, collecting, processing, analysing, storing, displaying, announcing, delivering, and/or disseminating electronic information.
- ESO: any persons, state administrators, business entities and the public that provide, manage and/or operate an electronic system individually or jointly to electronic system users for its own interests and/or the interests of another party.
- Public ESO: an electronic system operation by a state administrator agency or institutions appointed by a state administrator agency.
- Private ESO: an electronic system operated by a person, business entity, and the public.
With the entry into force of Regulation No. 71, Regulation No. 82 was repealed and declared null and void. Under Art. 17 of Regulation No. 82, ESOs for public services had to establish data centres and a disaster recovery centre in Indonesia, impacting many private sector companies.
Coverage Public electronic system operators

INDONESIA

Since March 2021

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Regulation No. 4/POJK.05/2021 - Implementation of Risk Management in the Use of Information Technology by Nonbank Financial Services Institutions (Peraturan Otoritas Jasa Keuangan Republik Indonesia Nomor 4 /pojk.05/2021 Tentang Penerapan Manajemen Risiko Dalam Penggunaan Teknologi Informasi Oleh Lembaga Jasa Keuangan Nonbank)
Under Art. 23 Regulation No. 4/05/2021, non-bank financial institutions are obligated to place their data centre and/or disaster recovery centre within the territory of Indonesia. An exemption of this obligation may only be applicable after obtaining prior approval from the Financial Services Authority (Otoritas Jasa Keuangan, OJK) and only for certain purposes of the electronic system.
Coverage Non-bank financial institutions

INDONESIA

Since April 2021

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
MOCI Regulation No. 3 of 2021 on Business Activity and Product Standards in Implementing Risk-Based Business Licensing in the Postal, Telecommunications and Electronic Systems and Transactions Sector (Peraturan Menteri Komunikasi dan Informatika Nomor 3 Tahun 2021 tentang Standar Kegiatan Usaha dan Standar Produk pada Penyelenggaraan Perizinan Berusaha Berbasis Risiko Sektor Pos, Telekomunikasi, dan Sistem dan Transaksi Elektronik)
Annex I of Regulation 3/2021 mandates that providers of electronic certification and digital signature services establish their systems within the territory of Indonesia.
Coverage Electronic certification and digital signature service providers

INDONESIA

Since October 2021, last amended in November 2022

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Regulation No. 8 of 2021 on Implementing Guideline of Physical Market Trading of Crypto Assets in the Futures Exchange (Nomor 8 Tahun 2021 Pedoman Penyelenggaraan Perdagangan Pasar Fisik Aset Kripto (Crypto Asset) di Bursa Berjangka)
Under Arts. 7, 11, 14 and 18 of Bappebti Regulation No. 8/2021, the stakeholders of crypto asset trade (i.e., futures market, futures clearing institution, crypto asset physical trader, and crypto asset depository manager) are obligated to place their disaster recovery centre as well as a server or cloud server within Indonesia. The disaster recovery centre must be located within a maximum distance of 20 km from the main server. A crypto asset is defined as a digital, intangible commodity that utilises cryptography, information technology networks, and distributed ledgers to create new units, verify transactions, and secure them without third-party intervention.
Coverage Stakeholders of crypto asset trade

INDONESIA

Since August 2023
Since July 2024
From May 2014 to July 2024

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Law No. 17 of 2023 on Health (Undang-undang (UU) Nomor 17 Tahun 2023 tentang Kesehatan)

Government Regulation No. 28 of 2024 on Implementing Regulation of Law No. 17 of 2023 on Health (Peraturan Pemerintah (PP) Nomor 28 Tahun 2024 tentang Peraturan Pelaksanaan Undang-Undang Nomor 17 Tahun 2023 tentang Kesehatan)

Government Regulation No. 46 of 2014 concerning Health Information Systems (Peraturan Pemerintah (PP) Nomor 46 Tahun 2014 tentang Sistem Informasi Kesehatan)
Art. 349.7 of the Law on Health requires that the international transfer of personal data managed by organisers of health information systems may only be carried out for specific and limited purposes, and must be subject to the approval of the central government. In addition, pursuant to Art. 966 of Government Regulation No. 28, organisers of health information systems are obliged to locate their data centres within the territory of Indonesia and to ensure their integration with the Indonesian national data centre. Additionally, Art. 970 stipulates that the transfer of health data and health information between organisers of health information systems must be conducted through the national health information system.
Government Regulation No. 28 repealed Government Regulation No. 46 of 2014, which, under Art. 21, required that health data be stored within the territory of Indonesia.
Coverage Health sector

Report issue     Report new measure