Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Southeast Asia

Indonesia: file security and audit obligations

Indonesia's PDP Law became fully enforceable in October 2024, but the supervisory authority it provides for has not yet been established, leaving enforcement running through the courts.

At a glance

How Indonesia regulates file security

  • 01

    Regime

    Comprehensive data protection statute; supervisory authority not yet established

  • 02

    File security

    PDP Law security obligations over personal data processing

  • 03

    Audit and evidence

    Breach notification under the PDP Law; sectoral requirements via OJK for finance

Overview

The regulatory picture

Indonesia's Personal Data Protection Law (UU PDP No. 27/2022) came into force on 17 October 2022 with a two-year transition period, becoming fully enforceable in October 2024. It requires controllers to protect personal data with appropriate security measures, notify breaches, and observe processing principles broadly modelled on the GDPR.

The practical picture is more complicated than the statute suggests. The supervisory authority the law provides for had not been established as the transition period elapsed, so enforcement has been running through the general courts, three personal-data criminal cases were decided by district courts during 2025, covering identity misuse, unauthorised access to government systems and unlawful account reactivation. For regulated sectors, OJK requirements for financial institutions remain the more immediately enforced control set.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Personal Data Protection Law (UU PDP No. 27/2022)KomdigiIn forceDirect

Komdigi

Personal Data Protection Law (UU PDP No. 27/2022)

In force 17 October 2022, fully enforceable from October 2024. Requires appropriate security measures over personal data, breach notification, and GDPR-style processing principles. The supervisory authority is not yet established.

Why it matters for file security. The security-measures obligation covers personal data wherever held, including in documents. With enforcement currently running through the courts, demonstrable technical controls carry evidentiary weight.

How Glasswall addresses it. Find & Redact reduces the personal data carried in documents before they are stored or shared, and Storage Monitor addresses the existing estate at rest, giving a controller concrete technical measures to point to.

Find & RedactStorage Monitor + SM AuditGlasswall Halo

Source: Komdigi

Latest developments

What has changed in Indonesia

Most recent first.

  1. In forceMedium impact

    PDP Law transition period ends; statute fully enforceable

    The two-year transition period under Indonesia's PDP Law elapsed, making the statute fully enforceable. The supervisory authority provided for by the law had not been established at that point.

    Why it matters for file security. Obligations are live even though the dedicated regulator is not, so controllers carry the compliance burden without the benefit of settled regulatory guidance.

    • banking
    • telco
    • healthcare

    Source: DLA Piper

Scope

About this page

This page is a working reference for organisations operating in Indonesia.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Indonesia?