Skip to the content
Global Data RulesData governance rules, country by country

Indonesia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Indonesia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

Indonesia's general privacy law lets data leave the country. You need one of three things. The destination protects the data about as well as Indonesia does. Or you use strong safeguards. Or the person agrees. Finance and health are different. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil, unless the financial regulator says otherwise. Electronic medical records must sit with a local storage provider.

Data governance in Indonesia

The eight things that decide how you handle data about people in Indonesia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The privacy law follows the data, not the office. It covers you whether you are inside or outside Indonesia. It applies if your use of personal data has legal effects in Indonesia, or affects people in Indonesia. There is no size or revenue cut-off to fall below. If you have no presence in the country, you are expected to name a representative in Indonesia. Any online service used by Indonesians is also expected to register with the digital ministry. The ministry can order internet providers to block services that do not register.

What you have to do here:
Appoint a representative · Register or notify
Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

In general yes, with homework. You must be able to show one of three things. The destination protects personal data at least as well as Indonesia does. Or you have put binding safeguards in place. Or the person clearly agreed. That general answer does not apply in finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres. They can only move abroad with written permission from the regulator. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself. Write down why it is safe enough, and keep that evidence. Finance works completely differently. You need real permission from the regulator before the systems move. The banking regulator allows itself up to three months to answer, once your paperwork is complete.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

It depends which rule you break. The privacy law's own watchdog is the weak spot. The law says the President must set up a supervisory body. We found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day, the digital ministry handles complaints, registration and blocking. The financial regulators are different. The Financial Services Authority and the central bank are plainly working. The Authority issued new binding rules as recently as July 2026.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There are minimums and a maximum, and they collide. The longest minimum is in health. A hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The maximum comes from the privacy law. You must erase personal data once the purpose is finished, the keeping period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins. So a patient asking for deletion does not defeat the 25-year rule.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count at least three deadlines, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. Banks have less time. You must send the financial regulator a first alert within 24 hours of learning about a serious technology incident. A full incident report follows within five working days. Other financial firms, such as insurers and lenders, have five working days. If you miss the 24-hour one, meeting the 72-hour one will not help you.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that ruin weekends. (1) In finance the barrier is a permission, not a contract. Moving systems abroad needs a licence from the regulator. The banking regulator gives itself up to three months to decide, so plan cloud migrations around that. (2) In health your cloud provider must have storage facilities in Indonesia. The Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally at risk. (5) A foreign company with no office still needs a named representative in Indonesia. And a consumer service that is not registered with the digital ministry can be blocked at the internet level.

What you have to do here:
Appoint a representative · Register or notify
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

One dated change is certain. From 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook. If you are in that business, re-check where your servers and records must sit. Two things are still pending, as far as we could verify. One is the detailed rulebook under the privacy law. The other is the presidential decision setting up the privacy watchdog itself. Both could land without warning.

What you have to do here:
Keep the data in the country
Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data must stay in the country

Official name: Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum · POJK 11/POJK.03/2022, articles 35, 36 and 60 · Directly binding regulation

In forceNo — it stays put

Banks must keep their electronic systems in data centres and disaster recovery centres inside Indonesia. Moving them abroad needs a licence from the Financial Services Authority (OJK), which may take up to three months to decide. Serious technology incidents must be reported within 24 hours.

In force since 7 July 2022

Enforced by Financial Services Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Payments

Payments data must stay in the country

Official name: Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran · PBI 23/6/PBI/2021, article 48 · Directly binding regulation

In forceNo — it stays put

Payment companies must handle the whole transaction chain inside Indonesia. The systems must sit in Indonesian data centres and back-up centres. Handling a payment abroad needs Bank Indonesia's approval.

In force since 1 July 2021

Enforced by Bank Indonesia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Insurance

Banking rules

Official name: Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank · POJK 4/POJK.05/2021, articles 23 and 31 · Directly binding regulation

In forceNo — it stays put

Insurers, finance companies, pension funds and other non-bank financial firms must place their electronic systems in Indonesian data centres and back-up centres. Placing them abroad is banned unless the Financial Services Authority (OJK) approves. Approval is normally given only for group risk management or anti-money-laundering purposes.

In force since 17 March 2021

Enforced by Financial Services Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi · Law 27 of 2022 · Act of parliament

In forceYes, with paperwork

The national privacy law covers companies abroad whose use of data affects people in Indonesia. Data may leave if the destination offers equal protection, or binding safeguards are in place, or the person consents. Fines can reach two percent of annual revenue, and some breaches are crimes.

In force since 17 October 2022Enforced from 17 October 2024

Enforced by Personal data protection supervisory body — not yet operational

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Lembaga Pelindungan Data Pribadi

    General privacy law supervision under Law 27 of 2022

    The law provides for a supervisory body answerable to the President. We could not find an official website, a membership list or any decision by such a body on 18 August 2026. The ministry's news pages could not be read by our automated tools. So we could not confirm the body is running.

  • Kementerian Komunikasi dan Digital

    Electronic system operator registration, access blocking, administration of the personal data protection law

    Runs the live public registration portal for private electronic system operators.

  • Otoritas Jasa Keuangan

    Banks, insurers, finance companies, pension funds, capital markets, and from 1 September 2026 digital financial assets and crypto

    Demonstrably active: issued Rule 3 of 2026 (30 June 2026), Regulation 8 of 2026 and Regulation 9 of 2026 (31 July 2026).

  • Bank Indonesia

    Payment systems and payment service providers

    Licenses and supervises payment service providers; publishes its regulations openly.

  • Kementerian Kesehatan

    Electronic medical records and health data

    Legal database is live and current; the ministry has direct access rights to electronic medical records.

  • Badan Informasi Geospasial

    Mapping and geospatial information

    Site and national geospatial portal are live; the agency's own legal database did not respond to automated requests today.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Article-level detail of Law 27 of 2022 — scope, the transfer test, the 72-hour breach deadline, the two percent revenue fine and the prison terms

    We could not confirm these details against the text of the law. Both official law databases refused us access on 18 August 2026. Treat these points as medium confidence and check them against the law before you rely on them.

  • Whether the personal data protection supervisory body has been constituted and is issuing decisions

    We could not confirm that the supervisory body exists and is working. If you need to deal with a privacy regulator in Indonesia, ask the digital ministry.

  • Whether the detailed implementing regulation under the personal data protection law has been issued

    We could not confirm whether the detailed rules under the privacy law have been issued. We state nothing either way. Check before you rely on the position.

  • The geospatial storage-in-Indonesia rule

    We could not confirm the rule that geospatial data must be stored in Indonesia. The geospatial agency's law database timed out. We carry it at low confidence and flag it in the rule itself. Check before you rely on it.

  • Telecoms-specific storage or retention rules for operators and their subscriber records

    We found no telecoms rule on where operator and subscriber records must sit, checked 18 August 2026. The digital ministry's law database refused every request. Confidence is low. This is an area we could not check, not a clean bill of health.

  • Rules for securities firms and capital-market participants on where systems and records may sit

    We could not confirm which rules apply to securities firms and capital-market participants. The financial regulator's non-bank technology rule covers insurers, finance companies and similar firms. Whether securities companies fall under it, or under a separate capital-market rule, is unresolved. Ask the regulator.

  • Cyber incident reporting duties to the national cyber agency, and the rules governing the National Data Centre used by government bodies

    We could not confirm cyber incident reporting duties to the national cyber agency, or the rules for the National Data Centre. The agency's site refused our requests and the National Data Centre portal did not load.

  • General record-keeping floors outside health — company documents, tax books, financial-sector records

    We could not confirm the minimum keeping periods outside health, so the retention answer states none for company documents, tax books and financial records. Check the rules that apply to your business.

  • Whether any of these findings has been overtaken by a development after roughly mid-2026 that is not published on the specific government pages reached

    We could not check for developments after roughly mid-2026 beyond the government sites we reached directly, because our search tool was unavailable. The financial regulator's material is recent: its database showed rules dated 31 July 2026.

  • The compliance deadline by which health facilities had to switch to electronic medical records

    We could not confirm the deadline by which health facilities had to switch to electronic medical records. So we state no start date for the health rule. The storage-location duty and the 25-year keeping period are confirmed.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.