Indonesia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Indonesia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Indonesia's general privacy law lets data leave the country. You need one of three things. The destination protects the data about as well as Indonesia does. Or you use strong safeguards. Or the person agrees. Finance and health are different. Banks, payment firms, insurers and non-bank lenders must run their systems on Indonesian soil, unless the financial regulator says otherwise. Electronic medical records must sit with a local storage provider.
Data governance in Indonesia
The eight things that decide how you handle data about people in Indonesia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The privacy law follows the data, not the office. It covers you whether you are inside or outside Indonesia. It applies if your use of personal data has legal effects in Indonesia, or affects people in Indonesia. There is no size or revenue cut-off to fall below. If you have no presence in the country, you are expected to name a representative in Indonesia. Any online service used by Indonesians is also expected to register with the digital ministry. The ministry can order internet providers to block services that do not register.
- What you have to do here:
- Appoint a representative · Register or notify
Law 27 of 2022 applies to the use of personal data inside Indonesia. It also applies to use outside Indonesia that has legal consequences in Indonesia, or consequences for people in Indonesia. If you are based outside the country, you must appoint a representative in Indonesia. That applies whether you decide how the data is used or you handle it for someone else. Separately, the electronic-systems rules require private electronic system operators serving Indonesian users to register. The ministry runs a public registration portal for this. The usual penalty for not registering is having your service blocked. Our detail on the privacy law is at medium confidence. The official law databases refused our automated access on 18 August 2026. See the unconfirmed list.
Sources
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
- Official sourceLink may be brokenBadan Pemeriksa Keuangan (Audit Board of Indonesia)Law 27 of 2022 on Personal Data Protection — full text in the Audit Board legal database (server refused the automated request on 18 August 2026)
peraturan.bpk.go.id
Link checked 18 August 2026
- Official sourceKementerian Komunikasi dan Digital (Ministry of Communication and Digital Affairs)Registration portal for private electronic system operators, run by the Ministry of Communication and Digital Affairs
pse.komdigi.go.id
Link checked 18 August 2026
Where the data is allowed to live
In general yes, with homework. You must be able to show one of three things. The destination protects personal data at least as well as Indonesia does. Or you have put binding safeguards in place. Or the person clearly agreed. That general answer does not apply in finance, health and government. Banks, payment providers, insurers and other non-bank financial firms must keep their systems in Indonesian data centres and back-up centres. They can only move abroad with written permission from the regulator. Electronic medical records must be stored with a provider that has storage facilities inside Indonesia.
- What you have to do here:
- Keep the data in the country
Industry by industry, on the evidence we found today. BANKING: closed, unless the Financial Services Authority grants a licence to place systems abroad (Regulation 11/POJK.03/2022). PAYMENTS: closed. Starting, authorising, clearing and settling a payment must all happen in Indonesia. The systems must sit in Indonesian data centres and disaster recovery centres. Handling a payment abroad needs Bank Indonesia's approval (Regulation 23/6/PBI/2021). INSURANCE, FINANCE COMPANIES, PENSION FUNDS AND OTHER NON-BANK FINANCIAL FIRMS: closed, unless the Financial Services Authority approves (Regulation 4/POJK.05/2021). HEALTH: electronic medical records may only be stored with an electronic system operator that has data storage facilities in the country. That comes from Minister of Health Regulation 24 of 2022. GOVERNMENT AND PUBLIC-SECTOR SYSTEMS: these must stay in Indonesia under the electronic systems regulation (Government Regulation 71 of 2019). Medium confidence. MAPPING AND GEOSPATIAL: we understand the geospatial law requires storage inside Indonesia. Low confidence, and listed in the unconfirmed list. TELECOMS: we verified no rule today, checked 18 August 2026. Confidence low. Crypto and digital financial asset trading moved under the Financial Services Authority's rulebook from 1 September 2026. Check its infrastructure requirements again after that date.
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 11/POJK.03/2022 on the use of information technology by commercial banks, articles 35, 36 and 60
ojk.go.id
“Bank wajib menempatkan Sistem Elektronik pada Pusat Data dan Pusat Pemulihan Bencana di wilayah Indonesia.”
Link checked 18 August 2026
- Official sourceBank Indonesia (central bank)Bank Indonesia Regulation 23/6/PBI/2021 on Payment Service Providers, article 48
bi.go.id
“Sistem elektronik yang digunakan untuk pemrosesan transaksi pada tahapan inisiasi, otorisasi, kliring, dan penyelesaian akhir ditempatkan pada pusat data dan pusat pemulihan bencana di wilayah Negara Kesatuan Republik Indonesia”
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 4/POJK.05/2021 on information technology risk management for non-bank financial institutions, articles 23 and 31
ojk.go.id
“LJKNB sebagaimana dimaksud pada ayat (1) dilarang menempatkan Sistem Elektronik pada Pusat Data dan/atau Pusat Pemulihan Bencana di luar wilayah Indonesia kecuali telah mendapatkan persetujuan dari Otoritas Jasa Keuangan.”
Link checked 18 August 2026
- Official sourceKementerian Kesehatan (Ministry of Health)Minister of Health Regulation 24 of 2022 on Medical Records, articles 20, 22, 28 and 39
jdih.kemkes.go.id
“Penyimpanan data Rekam Medis Elektronik di Fasilitas Pelayanan Kesehatan dilakukan paling singkat 25 (dua puluh lima) tahun sejak tanggal kunjungan terakhir Pasien”
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Government Regulation 71 of 2019 on the operation of electronic systems and transactions, articles 20 and 21 (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
There is no published list of approved countries and no official standard contract to sign. Under the general law you assess the destination yourself. Write down why it is safe enough, and keep that evidence. Finance works completely differently. You need real permission from the regulator before the systems move. The banking regulator allows itself up to three months to answer, once your paperwork is complete.
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · Government sign-off needed
The general law offers three routes, in order. First, the destination country protects data to an equal level. If not, adequate and binding safeguards. If not, the person's consent. We found no government list of approved countries and no official standard contract on any Indonesian government website on 18 August 2026. So you have to assess the destination yourself. The banking rule is explicit. Placing electronic systems abroad needs a licence from the Financial Services Authority (OJK). It will grant or refuse the licence 'paling lama 3 (tiga) bulan setelah seluruh persyaratan dipenuhi'. That means at the latest three months after all requirements are met. Payments and non-bank finance work the same way, with Bank Indonesia and the Financial Services Authority respectively.
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 11/POJK.03/2022 on the use of information technology by commercial banks, articles 35, 36 and 60
ojk.go.id
“Bank wajib menempatkan Sistem Elektronik pada Pusat Data dan Pusat Pemulihan Bencana di wilayah Indonesia.”
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 4/POJK.05/2021 on information technology risk management for non-bank financial institutions, articles 23 and 31
ojk.go.id
“LJKNB sebagaimana dimaksud pada ayat (1) dilarang menempatkan Sistem Elektronik pada Pusat Data dan/atau Pusat Pemulihan Bencana di luar wilayah Indonesia kecuali telah mendapatkan persetujuan dari Otoritas Jasa Keuangan.”
Link checked 18 August 2026
- Official sourceBank Indonesia (central bank)Bank Indonesia Regulation 23/6/PBI/2021 on Payment Service Providers, article 48
bi.go.id
“Sistem elektronik yang digunakan untuk pemrosesan transaksi pada tahapan inisiasi, otorisasi, kliring, dan penyelesaian akhir ditempatkan pada pusat data dan pusat pemulihan bencana di wilayah Negara Kesatuan Republik Indonesia”
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
It depends which rule you break. The privacy law's own watchdog is the weak spot. The law says the President must set up a supervisory body. We found no government source showing it is staffed and issuing decisions as of 18 August 2026. Day to day, the digital ministry handles complaints, registration and blocking. The financial regulators are different. The Financial Services Authority and the central bank are plainly working. The Authority issued new binding rules as recently as July 2026.
We rate this waking rather than active. Here is what we can see. The Financial Services Authority's own regulation database lists Rule 3 of 2026 on digital financial asset and crypto trading. It was set on 30 June 2026 and takes effect on 1 September 2026. The database lists Regulation 8 of 2026 on peer-to-peer lending transaction data reporting. And it lists Regulation 9 of 2026 on incidental reporting in the capital markets, derivatives and carbon exchange sectors, set and effective 31 July 2026. By contrast, we could not find any official page for a dedicated personal data protection authority. The ministry's own news pages could not be read by our automated tools. We are not saying that body does not exist. We are saying we could not verify that it does, checked 18 August 2026.
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority regulation database — most recent instruments, including POJK 9 of 2026 (31 July 2026) and POJK 8 of 2026
ojk.go.id
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Rule 3 of 2026 on trading in digital financial assets including crypto assets — set 30 June 2026, effective 1 September 2026
ojk.go.id
Link checked 18 August 2026
- Official sourceKementerian Komunikasi dan Digital (Ministry of Communication and Digital Affairs)Ministry of Communication and Digital Affairs — official site, the ministry that administers the personal data protection law
komdigi.go.id
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are minimums and a maximum, and they collide. The longest minimum is in health. A hospital or clinic must keep an electronic medical record for at least 25 years after the patient's last visit. Company and tax paperwork must also be kept for years. The maximum comes from the privacy law. You must erase personal data once the purpose is finished, the keeping period ends, or the person withdraws consent. Where they clash, the specific keeping rule wins. So a patient asking for deletion does not defeat the 25-year rule.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
Verified today. Minister of Health Regulation 24 of 2022 sets the health minimum. A health facility must keep the electronic medical record for at least 25 years from the date of the patient's last visit. The same regulation requires facilities to open the entire electronic medical record to the Ministry of Health. We did not re-check the financial-sector keeping periods, the ten-year company document rule or the tax bookkeeping periods against a government source. So we do not state them here. See the unconfirmed list. The privacy law's erasure duty is at medium confidence for the same reason.
Sources
- Official sourceKementerian Kesehatan (Ministry of Health)Minister of Health Regulation 24 of 2022 on Medical Records, articles 20, 22, 28 and 39
jdih.kemkes.go.id
“Penyimpanan data Rekam Medis Elektronik di Fasilitas Pelayanan Kesehatan dilakukan paling singkat 25 (dua puluh lima) tahun sejak tanggal kunjungan terakhir Pasien”
Link checked 18 August 2026
- Official sourceKementerian Kesehatan (Ministry of Health)Ministry of Health legal database record for Regulation 24 of 2022 on Medical Records
jdih.kemkes.go.id
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count at least three deadlines, and the privacy one is not the fastest. Under the privacy law you have 72 hours to tell the affected people and the regulator about a personal data breach. Banks have less time. You must send the financial regulator a first alert within 24 hours of learning about a serious technology incident. A full incident report follows within five working days. Other financial firms, such as insurers and lenders, have five working days. If you miss the 24-hour one, meeting the 72-hour one will not help you.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Verified today. Regulation 11/POJK.03/2022 requires a first alert 'notifikasi awal paling lama 24 (dua puluh empat) jam setelah insiden TI diketahui'. That means at the latest 24 hours after you learn of the technology incident. It also requires a full report 'paling lama 5 (lima) hari kerja setelah insiden TI diketahui'. That means at the latest five working days after you learn of it. Regulation 4/POJK.05/2021 covers non-bank financial institutions. They must report critical incidents, misuse or crime to the Financial Services Authority at the latest five working days after finding out. The 72-hour privacy-law deadline is three times 24 hours. It runs to the person affected and to the supervisory body. We carry it at medium confidence, because we could not read the text of the law. We did not verify cyber incident reporting duties to the national cyber agency. Its site refused our automated request.
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 11/POJK.03/2022 on the use of information technology by commercial banks, articles 35, 36 and 60
ojk.go.id
“Bank wajib menempatkan Sistem Elektronik pada Pusat Data dan Pusat Pemulihan Bencana di wilayah Indonesia.”
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 4/POJK.05/2021 on information technology risk management for non-bank financial institutions, articles 23 and 31
ojk.go.id
“LJKNB sebagaimana dimaksud pada ayat (1) dilarang menempatkan Sistem Elektronik pada Pusat Data dan/atau Pusat Pemulihan Bencana di luar wilayah Indonesia kecuali telah mendapatkan persetujuan dari Otoritas Jasa Keuangan.”
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that ruin weekends. (1) In finance the barrier is a permission, not a contract. Moving systems abroad needs a licence from the regulator. The banking regulator gives itself up to three months to decide, so plan cloud migrations around that. (2) In health your cloud provider must have storage facilities in Indonesia. The Ministry of Health can demand access to the whole medical record. (3) The 25-year medical record rule beats a patient's deletion request. (4) The privacy law carries prison sentences, not just fines, so directors are personally at risk. (5) A foreign company with no office still needs a named representative in Indonesia. And a consumer service that is not registered with the digital ministry can be blocked at the internet level.
- What you have to do here:
- Appoint a representative · Register or notify
- What it costs if you get it wrong:
- Criminal liability
Traps 1 and 2 are verified from the regulators' own texts. Trap 4: Law 27 of 2022 makes it a crime to obtain, disclose or use another person's personal data unlawfully. It carries prison terms and fines, and companies face multiplied fines. The exact terms are at medium confidence, because we could not read the text of the law today. Trap 5 combines the duty to appoint a representative under the privacy law with the electronic system operator registration the ministry runs. A sixth one to watch: the payments rule covers the transaction flow itself, not only stored records. Starting, authorising, clearing and settling a payment must all happen in Indonesia. That catches systems that route authorisation through a regional hub.
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 11/POJK.03/2022 on the use of information technology by commercial banks, articles 35, 36 and 60
ojk.go.id
“Bank wajib menempatkan Sistem Elektronik pada Pusat Data dan Pusat Pemulihan Bencana di wilayah Indonesia.”
Link checked 18 August 2026
- Official sourceKementerian Kesehatan (Ministry of Health)Minister of Health Regulation 24 of 2022 on Medical Records, articles 20, 22, 28 and 39
jdih.kemkes.go.id
“Penyimpanan data Rekam Medis Elektronik di Fasilitas Pelayanan Kesehatan dilakukan paling singkat 25 (dua puluh lima) tahun sejak tanggal kunjungan terakhir Pasien”
Link checked 18 August 2026
- Official sourceBank Indonesia (central bank)Bank Indonesia Regulation 23/6/PBI/2021 on Payment Service Providers, article 48
bi.go.id
“Sistem elektronik yang digunakan untuk pemrosesan transaksi pada tahapan inisiasi, otorisasi, kliring, dan penyelesaian akhir ditempatkan pada pusat data dan pusat pemulihan bencana di wilayah Negara Kesatuan Republik Indonesia”
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
What's changing next
One dated change is certain. From 1 September 2026 trading in digital financial assets, including crypto, runs under the financial regulator's new rulebook. If you are in that business, re-check where your servers and records must sit. Two things are still pending, as far as we could verify. One is the detailed rulebook under the privacy law. The other is the presidential decision setting up the privacy watchdog itself. Both could land without warning.
- What you have to do here:
- Keep the data in the country
POWERS ALREADY HELD, which matter more than pending bills. First, the electronic systems regulation lets the government treat groups of operators as public-scope. That pulls them into the rule that systems and data stay in Indonesia. The government can change that classification without new legislation. Second, the financial approvals for data centres abroad are permissions, not rights. The regulator can refuse them, attach conditions, or withdraw them. Third, the President can set up the privacy law's supervisory body at any time by regulation. That would switch on an enforcement route you cannot see today. Fourth, the ministry can order unregistered electronic services to be blocked. It can do that quickly, and it has done it to large platforms before.
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Rule 3 of 2026 on trading in digital financial assets including crypto assets — set 30 June 2026, effective 1 September 2026
ojk.go.id
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority regulation database — most recent instruments, including POJK 9 of 2026 (31 July 2026) and POJK 8 of 2026
ojk.go.id
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Government Regulation 71 of 2019 on the operation of electronic systems and transactions, articles 20 and 21 (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data must stay in the country
Official name: Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum · POJK 11/POJK.03/2022, articles 35, 36 and 60 · Directly binding regulation
Banks must keep their electronic systems in data centres and disaster recovery centres inside Indonesia. Moving them abroad needs a licence from the Financial Services Authority (OJK), which may take up to three months to decide. Serious technology incidents must be reported within 24 hours.
Enforced by Financial Services Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryElectronic systems must sit in a data centre and a disaster recovery centre inside Indonesia.
- Report cyber incidents — within 24 hoursFirst alert to the Financial Services Authority (OJK). Full report within five working days.
- Written vendor contractTechnology suppliers must agree to give the Financial Services Authority (OJK) access for inspection.
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory action for placing systems abroad without a licence
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 11/POJK.03/2022 on the use of information technology by commercial banks, articles 35, 36 and 60
ojk.go.id
“Bank wajib menempatkan Sistem Elektronik pada Pusat Data dan Pusat Pemulihan Bencana di wilayah Indonesia.”
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Regulation record page: 11/POJK.03/2022, in force 7 July 2022
ojk.go.id
Link checked 18 August 2026
Payments data must stay in the country
Official name: Peraturan Bank Indonesia Nomor 23/6/PBI/2021 tentang Penyedia Jasa Pembayaran · PBI 23/6/PBI/2021, article 48 · Directly binding regulation
Payment companies must handle the whole transaction chain inside Indonesia. The systems must sit in Indonesian data centres and back-up centres. Handling a payment abroad needs Bank Indonesia's approval.
Enforced by Bank Indonesia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryStarting, authorising, clearing and settling a payment must all happen in Indonesia, on systems held in Indonesian data centres and disaster recovery centres.
- Register or notifyPayment service providers are licensed by Bank Indonesia.
What it costs if you get it wrong
- Loss of your licenceBreach of payment service provider obligations
Sources
- Official sourceBank Indonesia (central bank)Bank Indonesia Regulation 23/6/PBI/2021 on Payment Service Providers, article 48
bi.go.id
“Sistem elektronik yang digunakan untuk pemrosesan transaksi pada tahapan inisiasi, otorisasi, kliring, dan penyelesaian akhir ditempatkan pada pusat data dan pusat pemulihan bencana di wilayah Negara Kesatuan Republik Indonesia”
Link checked 18 August 2026
- Official sourceBank Indonesia (central bank)Regulation record page: Bank Indonesia Regulation 23/6/PBI/2021, in force 1 July 2021
bi.go.id
Link checked 18 August 2026
Banking rules
Official name: Peraturan Otoritas Jasa Keuangan Nomor 4/POJK.05/2021 tentang Penerapan Manajemen Risiko dalam Penggunaan Teknologi Informasi oleh Lembaga Jasa Keuangan Nonbank · POJK 4/POJK.05/2021, articles 23 and 31 · Directly binding regulation
Insurers, finance companies, pension funds and other non-bank financial firms must place their electronic systems in Indonesian data centres and back-up centres. Placing them abroad is banned unless the Financial Services Authority (OJK) approves. Approval is normally given only for group risk management or anti-money-laundering purposes.
Enforced by Financial Services Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryData centre and disaster recovery centre inside Indonesia. Placing systems abroad is banned unless the Financial Services Authority (OJK) approves.
- Report cyber incidentsFive working days to report a critical incident, misuse or crime to the Financial Services Authority (OJK). Working days, not clock hours.
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory action for unapproved offshore placement
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Regulation 4/POJK.05/2021 on information technology risk management for non-bank financial institutions, articles 23 and 31
ojk.go.id
“LJKNB sebagaimana dimaksud pada ayat (1) dilarang menempatkan Sistem Elektronik pada Pusat Data dan/atau Pusat Pemulihan Bencana di luar wilayah Indonesia kecuali telah mendapatkan persetujuan dari Otoritas Jasa Keuangan.”
Link checked 18 August 2026
Health and social care data needs a copy kept in the country
Official name: Peraturan Menteri Kesehatan Nomor 24 Tahun 2022 tentang Rekam Medis · Minister of Health Regulation 24 of 2022, articles 20, 22, 28 and 39 · Directly binding regulation
Electronic medical records may only be stored with a provider that has storage facilities in Indonesia. They must be kept for at least 25 years after the patient's last visit. They must also be fully accessible to the Ministry of Health.
Enforced by Ministry of Health
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Keep the data in the countryYou may only use an outside storage provider that has data storage facilities inside the country. Cloud services must be certified.
- Keep data for a minimum period — 25 yearsAt least 25 years from the patient's last visit.
- Hold a security certificateCloud storage must be certified under Indonesian rules.
- Get consentPatient consent needed to disclose content, with exceptions for law enforcement and public health.
What it costs if you get it wrong
- Order to stopAdministrative sanctions on health facilities
Sources
- Official sourceKementerian Kesehatan (Ministry of Health)Minister of Health Regulation 24 of 2022 on Medical Records, articles 20, 22, 28 and 39
jdih.kemkes.go.id
“Penyimpanan data Rekam Medis Elektronik di Fasilitas Pelayanan Kesehatan dilakukan paling singkat 25 (dua puluh lima) tahun sejak tanggal kunjungan terakhir Pasien”
Link checked 18 August 2026
- Official sourceKementerian Kesehatan (Ministry of Health)Ministry of Health legal database record for Regulation 24 of 2022 on Medical Records
jdih.kemkes.go.id
Link checked 18 August 2026
Government data must stay in the country
Official name: Peraturan Pemerintah Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik · Government Regulation 71 of 2019, articles 20 and 21 · Directly binding regulation
Government and other public-scope electronic systems must be run and stored inside Indonesia. Private operators may store abroad but must register and keep Indonesian supervisors and law enforcement able to reach the data.
Enforced by Ministry of Communication and Digital Affairs
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryPublic-scope electronic system operators must run, handle and store their systems and data inside Indonesia.
- Register or notifyPrivate-scope operators must register with the ministry.
- Do not hand data to foreign authorities on demandOperators storing data abroad must still give Indonesian supervisors and law enforcement access to systems and data.
What it costs if you get it wrong
- Order to stopAccess blocking for unregistered or non-compliant operators
Sources
- Official sourceKementerian Hukum (national legal database)Government Regulation 71 of 2019 on the operation of electronic systems and transactions, articles 20 and 21 (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
- Official sourceKementerian Komunikasi dan Digital (Ministry of Communication and Digital Affairs)Registration portal for private electronic system operators, run by the Ministry of Communication and Digital Affairs
pse.komdigi.go.id
Link checked 18 August 2026
- Official sourceKementerian Komunikasi dan Digital (Ministry of Communication and Digital Affairs)Ministry of Communication and Digital Affairs — official site, the ministry that administers the personal data protection law
komdigi.go.id
Link checked 18 August 2026
Securities data rules
Official name: Peraturan ADK Nomor 3 Tahun 2026 tentang Penyelenggaraan Perdagangan Aset Keuangan Digital termasuk Aset Kripto · OJK Rule 3 of 2026 · Directly binding regulation
From 1 September 2026 trading in digital financial assets, including crypto, sits under the financial regulator's new rulebook. The earlier commodity-futures rules required Indonesian servers. We could not verify today whether the new rulebook repeats that.
Enforced by Financial Services Authority
How this country controls where data goes: Approval each time
What you have to do
- Register or notifyDigital asset and crypto trading operators are licensed and supervised by OJK from 1 September 2026.
What it costs if you get it wrong
- Loss of your licenceOperating without or against the licence
Sources
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority Rule 3 of 2026 on trading in digital financial assets including crypto assets — set 30 June 2026, effective 1 September 2026
ojk.go.id
Link checked 18 August 2026
- Official sourceOtoritas Jasa Keuangan (Financial Services Authority)Financial Services Authority regulation database — most recent instruments, including POJK 9 of 2026 (31 July 2026) and POJK 8 of 2026
ojk.go.id
Link checked 18 August 2026
Mapping and location data needs a copy kept in the country
Official name: Undang-Undang Nomor 4 Tahun 2011 tentang Informasi Geospasial · Law 4 of 2011, storage provisions · Act of parliament
Indonesia's geospatial law is understood to require mapping data and geospatial information to be stored inside the country. The national geospatial agency runs the official network. We could not check this against the text of the law today, so we carry it at low confidence.
Enforced by Geospatial Information Agency
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the countryStorage of geospatial data and information is understood to be required inside Indonesian territory. NOT VERIFIED on this run.
Sources
- Official sourceKementerian Hukum (national legal database)Law 4 of 2011 on Geospatial Information — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
- Official sourceBadan Informasi Geospasial (Geospatial Information Agency)Geospatial Information Agency — official site and national geospatial portal
big.go.id
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi · Law 27 of 2022 · Act of parliament
The national privacy law covers companies abroad whose use of data affects people in Indonesia. Data may leave if the destination offers equal protection, or binding safeguards are in place, or the person consents. Fines can reach two percent of annual revenue, and some breaches are crimes.
Enforced by Personal data protection supervisory body — not yet operational
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What you have to do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hoursThree times 24 hours. Medium confidence, because we could not read the text of the law.
- Tell affected people — within 72 hours
- Appoint a data protection officerRequired where you use data on a large scale, systematically, or in high-risk ways.
- Appoint a representativeFor companies based outside Indonesia, whether they decide how data is used or handle it for someone else.
- Assess high-risk projects — applies at: High-risk processing
- Delete data after a periodErase when the purpose ends, the retention period expires or consent is withdrawn.
What it costs if you get it wrong
- Percentage of global turnover: 2% of annual revenueAdministrative sanction for breach of the law's duties
- Order to stopTemporary suspension of processing activity
- Criminal liability: IDR 5-6 billion and imprisonment — about $370 thousandUnlawfully obtaining, disclosing or using another person's personal data
Sources
- Official sourceKementerian Hukum (national legal database)Law 27 of 2022 on Personal Data Protection — record in the national legal database (automated fetching blocked on 18 August 2026)
peraturan.go.id
Link checked 18 August 2026
- Official sourceLink may be brokenBadan Pemeriksa Keuangan (Audit Board of Indonesia)Law 27 of 2022 on Personal Data Protection — full text in the Audit Board legal database (server refused the automated request on 18 August 2026)
peraturan.bpk.go.id
Link checked 18 August 2026
- Official sourceKementerian Komunikasi dan Digital (Ministry of Communication and Digital Affairs)Ministry of Communication and Digital Affairs — official site, the ministry that administers the personal data protection law
komdigi.go.id
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Article-level detail of Law 27 of 2022 — scope, the transfer test, the 72-hour breach deadline, the two percent revenue fine and the prison terms
We could not confirm these details against the text of the law. Both official law databases refused us access on 18 August 2026. Treat these points as medium confidence and check them against the law before you rely on them.
Whether the personal data protection supervisory body has been constituted and is issuing decisions
We could not confirm that the supervisory body exists and is working. If you need to deal with a privacy regulator in Indonesia, ask the digital ministry.
Whether the detailed implementing regulation under the personal data protection law has been issued
We could not confirm whether the detailed rules under the privacy law have been issued. We state nothing either way. Check before you rely on the position.
The geospatial storage-in-Indonesia rule
We could not confirm the rule that geospatial data must be stored in Indonesia. The geospatial agency's law database timed out. We carry it at low confidence and flag it in the rule itself. Check before you rely on it.
Telecoms-specific storage or retention rules for operators and their subscriber records
We found no telecoms rule on where operator and subscriber records must sit, checked 18 August 2026. The digital ministry's law database refused every request. Confidence is low. This is an area we could not check, not a clean bill of health.
Rules for securities firms and capital-market participants on where systems and records may sit
We could not confirm which rules apply to securities firms and capital-market participants. The financial regulator's non-bank technology rule covers insurers, finance companies and similar firms. Whether securities companies fall under it, or under a separate capital-market rule, is unresolved. Ask the regulator.
Cyber incident reporting duties to the national cyber agency, and the rules governing the National Data Centre used by government bodies
We could not confirm cyber incident reporting duties to the national cyber agency, or the rules for the National Data Centre. The agency's site refused our requests and the National Data Centre portal did not load.
General record-keeping floors outside health — company documents, tax books, financial-sector records
We could not confirm the minimum keeping periods outside health, so the retention answer states none for company documents, tax books and financial records. Check the rules that apply to your business.
Whether any of these findings has been overtaken by a development after roughly mid-2026 that is not published on the specific government pages reached
We could not check for developments after roughly mid-2026 beyond the government sites we reached directly, because our search tool was unavailable. The financial regulator's material is recent: its database showed rules dated 31 July 2026.
The compliance deadline by which health facilities had to switch to electronic medical records
We could not confirm the deadline by which health facilities had to switch to electronic medical records. So we state no start date for the health rule. The storage-location duty and the 25-year keeping period are confirmed.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.