Indonesian Political, Business & Finance News

Data Protection Agency Still Non-Existent in Indonesia Despite Existing Regulations

| Source: CNBC Translated from Indonesian | Regulation
Data Protection Agency Still Non-Existent in Indonesia Despite Existing Regulations
Image: CNBC

The Personal Data Protection Law (UU PDP) was passed in October 2022. However, to date, the Personal Data Protection Agency, which is tasked with the functions of supervision and enforcement of compliance with these regulations, has not yet been formed.

Executive Director of Catalyst Policy-Works, Wahyudi Djafar, stated that based on Article 74 of the UU PDP, the adjustment period ended two years after the law was enacted, specifically in October 2024. This implies that personal data protection compliance standards should have been implemented since that time.

Nevertheless, such implementation heavily relies on technical regulations and a specialised agency to ensure adherence to the UU PDP.

It was only in August 2026 that the government finally enacted Government Regulation (PP) Number 33 of 2026 as the implementing regulation for the UU PDP. However, according to Wahyudi, the application of these rules still faces significant obstacles because the Personal Data Protection Agency is not yet operational.

This is because the agency plays a crucial role in providing technical guidance regarding the application of compliance standards, including mechanisms for data transfers, which in several provisions refer directly to the guidance provided by said agency.

“Because the agency, or the Personal Data and Protection Agency, has not yet been formed, it is difficult to operate, run, and implement the compliance standards regulated in that Government Regulation,” Wahyudi told CNBC Indonesia via telephone on Tuesday (15/09/2026).

He explained that the process of forming the agency has actually been underway for quite some time. The initial permit for drafting the Presidential Regulation (Perpres) regarding the Personal Data Protection Agency was even submitted in 2024. However, the process has not yielded results to date due to the political transition during that year.

“There was a political process at that time, the political transition in 2024, and unfortunately, the Presidential Regulation regarding the formation of this agency has not yet been issued,” he revealed.

According to Wahyudi, even if the Presidential Regulation is issued this year, the agency will not be able to operate instantly. The government will still require time to establish an organisational structure, prepare human resources, allocate a budget, and formulate mature working mechanisms.

“Therefore, it will likely take another 1-2 years before it can operate effectively and perform the functions mandated by the UU PDP and Government Regulation Number 33 of 2026,” he explained.

Representation from Various Parties Required

Wahyudi believes that the Personal Data Protection Agency must be built as a strong and independent institution. Therefore, its composition needs to involve various stakeholders who truly understand business processes and the procedures for protecting and processing personal data.

In his view, the necessary elements to be represented include industry players, technology groups, civil society, academics, and the government itself.

“It should represent industry, technology groups, civil society, academics, and also the government. Because the government is also a data controller in this context,” said Wahyudi.

He emphasised that the composition, structure, and human resource requirements for the agency must be formulated transparently and clearly within the Presidential Regulation governing its formation.

Implementation Remains Voluntary

With the supervisory agency yet to be formed, Wahyudi noted that the implementation of several PDP compliance standards is currently still voluntary.

“Even if data controllers today wish to implement some of those compliance standards, as mentioned, it is still voluntary, because there is no agency specifically supervising how those compliance standards are implemented,” he explained.

Nonetheless, this does not mean all aspects of data protection are entirely exempt from oversight. For electronic system providers (PSE), the Ministry of Communication and Digital (Komdigi) still maintains legitimate supervisory authority based on Government Regulation Number 71 of 2019.

Furthermore, the criminal sanction provisions in the UU PDP have been enforceable since the law officially came into effect. Wahyudi noted that several cases allegedly involving criminal violations of personal data protection have already been processed through the legal system up to the courts.

“When there is a criminal violation, it has actually been enforced since 2022,” he said.

However, he highlighted that criminal law enforcement is different in nature from the enforcement of administrative compliance standards. For administrative aspects directly related to UU PDP compliance, the authority for supervision and enforcement rests solely with the Personal Data Protection Agency.

“Consequently, what can be effectively applied is limited to criminal law violations. This is because the UU PDP regulates criminal threats; the process involves the police, the prosecutor’s office, and ultimately the courts,” he concluded.

View JSON | Print