What breaking Indonesia’s PDP Law can cost: fines, prison terms and personal liability

Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) punishes violations in two ways. The PDP authority can impose administrative sanctions, including fines of up to 2% of annual income or revenue. Some acts are also crimes, and when a corporation commits one, its management can be held liable alongside the company.

For comparison, the GDPR, the European Union’s data protection law, allows fines of up to 4% of global annual turnover. Indonesia’s ceiling is lower, but the criminal side and the personal liability make the law a board-level matter.

The regulator’s toolkit

Administrative sanctions are imposed by the PDP authority (lembaga PDP), the supervisory body for the law. They are:

  • a written warning;
  • temporary suspension of processing activities;
  • erasure or destruction of personal data;
  • an administrative fine of up to 2% of annual income or revenue attributable to the violation.

Suspension can hurt more than the fine. An order to stop processing can halt a product or service that depends on customer data.

How big can the fine be?

The 2% is calculated on the income or revenue attributable to the violation. As a simple example, if that revenue is IDR 1 trillion, the maximum administrative fine is IDR 20 billion. Civil damages, litigation costs and reputational harm would come on top of that.

When it becomes a crime

Articles 67-73 set out the criminal offenses. Each carries a prison term, a fine, or both.

Offense Maximum prison term Maximum fine
Unlawfully obtaining or collecting personal data that does not belong to the offender 5 years IDR 5 billion (Rp5 miliar)
Unlawfully disclosing personal data that does not belong to the offender 4 years IDR 4 billion
Unlawfully using personal data that does not belong to the offender 5 years IDR 5 billion
Creating false personal data or falsifying personal data 6 years IDR 6 billion

Courts can also order additional penalties: confiscation of profits or assets derived from the offense, and payment of compensation.

Corporations face criminal fines of up to 10 times the maximum fine prescribed. For data falsification, that means up to IDR 60 billion. Additional penalties for corporations include suspension of business and revocation of licenses.

Who can be held responsible?

If a corporation commits an offense, penalties may be imposed on management, controlling persons, those who gave the orders, beneficial owners, and/or the corporation itself. Responsibility does not stop with the IT team.

For directors, this means the absence of a board-approved data protection policy is a direct personal risk. Do not count on insurance either: cyber insurance policies generally do not cover criminal fines.

What the board should ask management

A board can gauge its exposure quickly by asking for evidence on these points:

  1. Do we have a record of processing activities (ROPA), a register of every way we use personal data?
  2. Have we carried out data protection impact assessments (DPIAs) for our high-risk processing?
  3. Can we show that we would notify the regulator and the people affected within 72 hours (3x24 jam) of a data breach?

If the answer to any of these is no, sanctions exposure increases. Our 12-week compliance roadmap shows how to close those gaps in order.