Regulatory landscape ยท Southeast Asia
Indonesia: file security and audit obligations
Indonesia's PDP Law became fully enforceable in October 2024, but the supervisory authority it provides for has not yet been established, leaving enforcement running through the courts.
At a glance
How Indonesia regulates file security
- 01
Regime
Comprehensive data protection statute; supervisory authority not yet established
- 02
File security
PDP Law security obligations over personal data processing
- 03
Audit and evidence
Breach notification under the PDP Law; sectoral requirements via OJK for finance
Overview
The regulatory picture
Indonesia's Personal Data Protection Law (UU PDP No. 27/2022) came into force on 17 October 2022 with a two-year transition period, becoming fully enforceable in October 2024. It requires controllers to protect personal data with appropriate security measures, notify breaches, and observe processing principles broadly modelled on the GDPR.
The practical picture is more complicated than the statute suggests. The supervisory authority the law provides for had not been established as the transition period elapsed, so enforcement has been running through the general courts, three personal-data criminal cases were decided by district courts during 2025, covering identity misuse, unauthorised access to government systems and unlawful account reactivation. For regulated sectors, OJK requirements for financial institutions remain the more immediately enforced control set.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Personal Data Protection Law (UU PDP No. 27/2022) | Komdigi | In force | Direct |
Komdigi
Personal Data Protection Law (UU PDP No. 27/2022)
In force 17 October 2022, fully enforceable from October 2024. Requires appropriate security measures over personal data, breach notification, and GDPR-style processing principles. The supervisory authority is not yet established.
Why it matters for file security. The security-measures obligation covers personal data wherever held, including in documents. With enforcement currently running through the courts, demonstrable technical controls carry evidentiary weight.
How Glasswall addresses it. Find & Redact reduces the personal data carried in documents before they are stored or shared, and Storage Monitor addresses the existing estate at rest, giving a controller concrete technical measures to point to.
Find & RedactStorage Monitor + SM AuditGlasswall Halo
Latest developments
What has changed in Indonesia
Most recent first.
-
PDP Law transition period ends; statute fully enforceable
The two-year transition period under Indonesia's PDP Law elapsed, making the statute fully enforceable. The supervisory authority provided for by the law had not been established at that point.
Why it matters for file security. Obligations are live even though the dedicated regulator is not, so controllers carry the compliance burden without the benefit of settled regulatory guidance.
- banking
- telco
- healthcare
Elsewhere in the region
Other APAC territories
Scope
About this page
This page is a working reference for organisations operating in Indonesia.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.