Skip to the content
Global Data RulesData governance rules, country by country

Indonesia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Waking up

Indonesia's general privacy law lets data leave if the destination protects it about as well as Indonesia does, or you use strong safeguards, or the person agrees. Money and health are walled off. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil unless the financial regulator says otherwise, and medical records must sit with a local storage provider.

Eight questions about Indonesia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Indonesia's rules apply to my company?

Yes. The privacy law follows the data, not the office. It covers any organisation, inside or outside Indonesia, whose handling of personal data has legal effects in Indonesia or affects people in Indonesia. There is no size or revenue cut-off to fall below. An organisation with no presence in the country is expected to name a representative in Indonesia, and any online service used by Indonesians is also expected to register with the digital ministry, which can order internet providers to block services that do not.

Medium confidenceNational rulesAppoint a local representativeRegister or notify

Can I store my users' data outside Indonesia?

In general yes, with homework. You must be able to show the destination protects personal data at a level at least equal to Indonesia's, or put binding safeguards in place, or get the person's clear agreement. That general answer stops at the door of finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres, and can only go offshore with written regulator permission. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.

High confidenceDepends on your industryApproval each timeKeep the data in the country

What do I need in place before data leaves Indonesia?

There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself, write down why it is safe enough, and keep that evidence. In finance the model is completely different: you need a real permission from the regulator before the systems move, and the banking regulator allows itself up to three months to answer once your paperwork is complete.

Medium confidenceApproval each timeOfficial 'this country is safe' decisionExplicit consentGovernment sign-off needed

Who enforces the rules in Indonesia, and what can they do?

It depends which rule you break. The privacy law's own watchdog is the weak spot: the law says a supervisory body must be set up by the President, and we found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day the digital ministry handles complaints, registration and blocking. The financial regulators are a different story — the Financial Services Authority and the central bank are plainly working, and the Authority issued new binding rules as recently as July 2026.

Medium confidenceWaking up

How long do I have to keep the data?

There is a floor and a ceiling and they collide. The hardest floor is health: a hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The ceiling comes from the privacy law, which says personal data must be erased once the purpose is finished, the retention period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins, so a patient asking for deletion does not defeat the 25-year rule.

High confidenceKeep data for a minimum periodDelete data after a periodLet people delete their data

What happens if there is a breach?

Count at least three clocks, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. If you are a bank, you must send the financial regulator a first alert within 24 hours of learning about a serious technology incident, and a full incident report within five working days. Other financial firms, such as insurers and lenders, have five working days. Miss the 24-hour one and the fact that you met the 72-hour one will not help you.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Indonesia?

Five things that ruin weekends. (1) In finance the wall is a permission, not a contract — moving systems abroad needs a regulator licence and the banking regulator gives itself up to three months to decide, so cloud migrations must be planned around that. (2) In health your cloud provider must have storage facilities in Indonesia, and the Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally exposed. (5) A foreign company with no office still needs a named representative in Indonesia, and a consumer service that is not registered with the digital ministry can be blocked at the internet level.

Medium confidenceCriminal liabilityAppoint a local representativeRegister or notifyKeep the data in the countryKeep data for a minimum period

What is changing soon in Indonesia?

One dated change is certain: from 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook, so anyone in that business should re-check where its servers and records must sit. Two things are still pending as far as we could verify: the detailed implementing regulation under the privacy law, and the presidential decision setting up the privacy watchdog itself. Both could land without warning.

Medium confidenceIn forceKeep the data in the country

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    1 rule here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules1 rule

Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi

Act of parliament · Law 27 of 2022

In forceYes, with paperwork

The national privacy law covers organisations abroad whose processing affects people in Indonesia. Data may leave if the destination offers equivalent protection, or binding safeguards are in place, or the person consents. Fines can reach two percent of annual revenue and some breaches are crimes.

In force since 17 October 2022But only enforceable from 17 October 2024

Enforced by Personal data protection supervisory body — not yet operational

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Medium confidence

Industry rules7 rules

Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum

Directly binding regulation · POJK 11/POJK.03/2022, articles 35, 36 and 60 · Banking

In forceNo — it stays put

Banks must keep their electronic systems in data centres and disaster recovery centres inside Indonesia. Going offshore needs an OJK licence, and OJK may take up to three months to decide. Serious technology incidents must be flagged within 24 hours.

In force since 7 July 2022

Enforced by Financial Services Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran

Directly binding regulation · PBI 23/6/PBI/2021, article 48 · Payments

In forceNo — it stays put

Payment companies must process the whole transaction chain inside Indonesia and hold the systems in Indonesian data centres and back-up centres. Processing a payment abroad requires Bank Indonesia's approval.

In force since 1 July 2021

Enforced by Bank Indonesia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank

Directly binding regulation · POJK 4/POJK.05/2021, articles 23 and 31 · Insurance

In forceNo — it stays put

Insurers, finance companies, pension funds and other non-bank financial firms must place their electronic systems in Indonesian data centres and back-up centres. Offshore placement is prohibited unless OJK approves it, and it is normally allowed only for group risk management or anti-money-laundering purposes.

In force since 17 March 2021

Enforced by Financial Services Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Lembaga Pelindungan Data Pribadi

    General privacy law supervision under Law 27 of 2022

    The law provides for a supervisory body answerable to the President. No official website, membership list or decision by such a body could be located on 18 August 2026, and the ministry's news pages could not be read by an automated fetcher. This is an unverified negative, not a proven one: treat it as 'not evidenced' rather than 'does not exist'.

  • Kementerian Komunikasi dan Digital

    Electronic system operator registration, access blocking, administration of the personal data protection law

    Runs the live public registration portal for private electronic system operators.

  • Otoritas Jasa Keuangan

    Banks, insurers, finance companies, pension funds, capital markets, and from 1 September 2026 digital financial assets and crypto

    Demonstrably active: issued Rule 3 of 2026 (30 June 2026), Regulation 8 of 2026 and Regulation 9 of 2026 (31 July 2026).

  • Bank Indonesia

    Payment systems and payment service providers

    Licenses and supervises payment service providers; publishes its regulations openly.

  • Kementerian Kesehatan

    Electronic medical records and health data

    Legal database is live and current; the ministry has direct access rights to electronic medical records.

  • Badan Informasi Geospasial

    Mapping and geospatial information

    Site and national geospatial portal are live; the agency's own legal database did not respond to automated requests today.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Article-level detail of Law 27 of 2022 — scope, the transfer test, the 72-hour breach deadline, the two percent revenue fine and the prison terms

    Both official statute databases refused automated access on 18 August 2026: the national legal database blocked the fetcher at robots level and the Audit Board database returned an access-denied response. These claims are carried at medium confidence and must be re-read against the statute at the next refresh.

  • Whether the personal data protection supervisory body has been constituted and is issuing decisions

    No government page for such a body could be located, and the ministry's news and press-release pages render only through JavaScript, so an automated fetch returns navigation only. We can evidence that we did not find it; we cannot prove it does not exist.

  • Whether the detailed implementing regulation under the personal data protection law has been issued

    Could not be confirmed either way from a government source on this run. Not asserted in either direction.

  • The geospatial storage-in-Indonesia rule

    The geospatial agency's legal database timed out and the statute text could not be fetched. Carried at low confidence and flagged in the rule itself.

  • Telecoms-specific storage or retention rules for operators and their subscriber records

    The digital ministry's legal database returned an access-denied response to every automated request today. No rule found, checked 18 August 2026, confidence low — this is an unchecked area, not a clean bill of health.

  • Rules for securities firms and capital-market participants on where systems and records may sit

    The financial regulator's non-bank technology rule covers insurers, finance companies and similar institutions; whether securities companies fall under it or under a separate capital-market instrument was not resolved today.

  • Cyber incident reporting duties to the national cyber agency, and the rules governing the National Data Centre used by government bodies

    The national cyber agency's site refused automated requests and the National Data Centre portal did not resolve.

  • General record-keeping floors outside health — company documents, tax books, financial-sector records

    Not re-verified against a government source on this run, so deliberately not asserted in the retention answer.

  • Whether any of these findings has been overtaken by a development after roughly mid-2026 that is not published on the specific government pages reached

    The web search tool was unavailable for this run, so discovery was limited to directly addressed government sites. Recency is evidenced for the financial regulator, whose database showed instruments dated 31 July 2026.

  • The compliance deadline by which health facilities had to switch to electronic medical records

    The regulation's transitional deadline was not re-read today, so no 'bites from' date is asserted for the health rule; only the storage-location and 25-year retention duties are evidenced.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.