Indonesian Political, Business & Finance News

Indonesian Citizens' Data Stored Abroad, Experts Issue Warning

| Source: CNBC Translated from Indonesian | Regulation
Indonesian Citizens' Data Stored Abroad, Experts Issue Warning
Image: CNBC

Digital platforms such as Facebook and Instagram are known to store user data outside of Indonesian territory. Wahyudi Djafar, Executive Director of Catalyst Policy-Works, explained that the Personal Data Protection Law (UU PDP) does not specifically mandate data localisation or the determination of physical data storage locations.

According to him, the UU PDP focuses more on regulating the mechanisms of personal data transfers, including when data is sent from within the country to abroad. Meanwhile, technical provisions regarding data storage are regulated under Government Regulation (PP) Number 71 of 2019, which is further detailed through Ministry of Communication and Digital Affairs Regulation Number 5 of 2025 concerning Electronic System Providers (PSE) in the public scope.

“There is a classification of public data and how the storage process works,” Wahyudi told CNBC Indonesia via telephone on Wednesday (16/9/2026).

Wahyudi explained that the UU PDP allows the personal data of Indonesian citizens to be transferred abroad, provided that the destination country has a level of legal protection equivalent to Indonesia’s PDP regulations. This provision is clearly stated in Article 56 of the UU PDP. The absolute requirement for this cross-border data transfer is the equivalence of personal data protection levels between Indonesia and the destination country.

“So, the main requirement is equivalence. If that equivalence is not achieved, it means it does not exist. For example, if data is to be transferred to the United States, but it turns out the United States is not considered equivalent to Indonesia,” he explained.

Nevertheless, if the destination country does not meet that level of equivalence, the data transfer process can still proceed through certain exceptions. One valid legal loophole is obtaining explicit consent from the data subject involved.

“Therefore, the exception clause allows transfers to proceed if there is explicit consent—clear permission from the data subject allowing their data to be transferred abroad,” said Wahyudi.

He added that the mechanism for assessing the level of equivalence of the destination country has been further regulated through PP Number 33 of 2026. This regulation contains various obligations that data controllers must comply with when intending to move personal data from Indonesia outside the country’s sovereign territory.

One of the primary obligations for data controllers is to conduct a risk assessment of the data transfer scheme being implemented.

“Unfortunately, regarding how to conduct the risk assessment, the process and details will eventually be regulated through guidelines issued by the Personal Data Protection Agency,” he revealed.

Crucial Issues in Protecting Indonesian Citizens’ Personal Data

According to Wahyund, the fundamental problem arises because the Personal Data Protection Agency, which should serve as the primary reference for executing these functions, has not yet been formed. Technical guidelines regarding risk assessments are also not yet available.

In addition to risk assessments, the Personal Data Protection Agency will also hold full authority to assess the level of legal protection equivalence in the destination countries for personal data transfers.

Wahyudi believes this institutional vacuum is a serious obstacle to the implementation of cross-border personal data transfer regulations. He noted that although the substantive requirements for transfers have been normatively regulated, the operational technical rules and the overseeing supervisory body are not yet fully functional.

“That is the problem. So, even though the transfer requirements and the obligations of data controllers when transferring personal data from Indonesia to outside Indonesia have been regulated, the technical regulatory reference is still non-existent,” he emphasised.

He also stressed that the presence of such an agency is a crucial element for the UU PDP to be implemented optimally in the field. The agency, according to him, must be supported by adequate authority so that the UU PDP can be applied effectively.

“Therefore, without a strong and independent Personal Data Protection Agency, it will be difficult for the UU PDP to be implemented effectively,” he concluded.

View JSON | Print