Law / Indonesia

Indonesia

14 of 15 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 16 September 2026.

When they take effect14 of 14 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 3 instruments (3 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 2 instruments (2 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 6 instruments (6 in force) 2023: 0 instruments 2024: 0 instruments 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 4
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (223 words)

Indonesia has no binding statute or regulation dedicated to AI-transparency, output-labelling, or risk-classification duties for an AI system as such.

The Electronic Information and Transactions Law's electronic-agent provisions, in force since 2008 and unaffected by the Law's 2016 and 2024 amendments, allocate legal responsibility to whoever operates an automated system used to conduct an electronic transaction, a definition that reaches a chatbot or another AI-driven agent, and require certain electronic-agent operators to let a user correct information before a transaction completes.

Indonesia's Personal Data Protection Law gives a data subject a right to object to a decision based solely on automated processing, including profiling, that has a legal or significant effect; that duty attaches to the processing of personal data rather than to the use of AI as such and is documented under the privacy topic.

Two instruments describe AI-specific conduct without binding anyone: Ministry of Communication and Digital Affairs (Komdigi, formerly Kominfo) Circular Letter No. 9 of 2023 sets out seven non-binding ethical principles for AI use, and the Financial Services Authority (OJK) has issued and updated a non-binding sectoral Code of Ethics for AI use in financial technology.

Two draft Presidential Regulations, one on AI ethics and safety and one on a national AI roadmap, were reported in mid-2026 government drafting materials as still awaiting signature and are not yet law.

AI governance

Electronic Information and Transactions Law, electronic agent liability

Law No. 11 of 2008, Articles 21-22, Electronic Information and Transactions LawMinistry of Communication and Digital Affairs' own legal-documentation network (JDIH Komdigi), official consolidated text

In force since 21 April 2008. Binds public and private bodies.

What this law does

Article 1 defines an Electronic Agent as a device of an Electronic System built to perform an action against particular electronic information automatically, on behalf of a Person, a definition that reaches a chatbot, an automated transaction system, or another AI-driven agent acting without a human directly initiating each step.

Article 21 allocates legal responsibility for an electronic transaction conducted through an Electronic Agent to the party who operates that Electronic Agent, and separately makes the operator of a failed Electronic Agent responsible for resulting loss where the failure was caused by a third party's direct action against the Electronic System.

Article 22 requires the operator of a certain Electronic Agent to provide a feature letting a user correct information while a transaction is still in process, with further detail on which operators this reaches left to a Government Regulation. Neither provision has been amended by the Law's 2016 or 2024 amendments.

What it requires

Privacy law5 instruments, 5 in force

Research summary (196 words)

Indonesia's comprehensive private-sector data-protection law is Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi, UU PDP), signed and promulgated 17 October 2022, with a two-year adjustment period reported to have ended 17 October 2024.

Article 4 distinguishes specific personal data, the sensitive category, from general personal data; the official elucidation to Article 4(2)(b) defines biometric data as data enabling unique identification from a person's physical, physiological, or behavioral characteristics, naming a facial image expressly and, more broadly, reaching a voice-derived identifier on the same general language.

The Act's substantive duties, including consent, sensitive-category handling, breach notification, cross-border adequacy, and data-subject rights, are themselves statutory and binding today, but nine mandated implementing regulations (Peraturan Pemerintah) remained unissued and the dedicated supervisory institution had not been formally established as of the date shown, so the procedural mechanics for several duties, including the fine-calculation procedure and the automated-decision objection procedure, are left to regulations that do not yet exist.

Article 12 grants a statutory right to sue for compensation, and Article 57 sets an administrative fine of up to 2 percent of annual revenue, with its own imposition procedure likewise awaiting the pending regulation.

Biometric privacy

Law on Personal Data Protection, biometric data definition

Law No. 27 of 2022 on Personal Data Protection, Article 4(2)(b) and its official elucidationgovernment (.go.id) legal-documentation network mirror

In force since 17 October 2022. Binds public and private bodies.

What this law does

Article 4 distinguishes specific personal data (the sensitive category) from general personal data, listing biometric data among health data, genetic data, criminal records, children's data, and personal financial data. The official elucidation to Article 4(2)(b) defines biometric data as data relating to a person's physical, physiological, or behavioral characteristics enabling unique identification, naming a facial image expressly as an example alongside fingerprint, retinal, and DNA data.

A direct search for suara (voice) in the elucidation returned zero hits, so voiceprint coverage rests on the general definitional language rather than an express example. As specific personal data, biometric data processing requires stricter consent under Article 21 and related provisions.

What it requires

Breach notification

Law on Personal Data Protection, breach notification

Law No. 27 of 2022 on Personal Data Protection, Article 46government (.go.id) legal-documentation network mirror

In force since 17 October 2022. Binds public and private bodies.

What this law does

Article 46(1) requires a Personal Data Controller to give written notification no later than 3 times 24 hours (72 hours) to the personal data subject and to the supervisory institution on a failure of personal data protection. The notification must at minimum describe the data disclosed, when and how it was disclosed, and the controller's handling and recovery efforts; in certain cases the controller must also notify the public.

What it requires

Comprehensive regime

Law on Personal Data Protection, comprehensive regime

Law No. 27 of 2022 on Personal Data Protection, State Gazette 2022 No. 196, signed and promulgated 17 October 2022government (.go.id) legal-documentation network mirror

In force since 17 October 2022. Binds public and private bodies.

What this law does

Law No. 27 of 2022 (UU PDP) is Indonesia's first standalone, comprehensive personal-data statute, running lawful basis primarily through Article 20's consent model. Enforcement and rulemaking authority sits with a to-be-established supervisory institution under Chapter IX, referred to in the Act as lembaga; as of the date shown, that institution had not been formally established, with a draft Presidential Regulation on it still in stakeholder discussion.

Nine mandated Peraturan Pemerintah delegated implementing detail, including the fine-calculation procedure, the automated-decision objection procedure, and the compensation-claim procedure, and remained unissued as of the date shown, though the Act's own substantive duties are themselves statutory and binding now. The Act's text is cited from a city-government legal-documentation network (JDIH) copy, corroborated against the national Audit Board's legal database.

What it requires

Cross border transfer

Law on Personal Data Protection, cross-border transfer

Law No. 27 of 2022 on Personal Data Protection, Article 56government (.go.id) legal-documentation network mirror

In force since 17 October 2022. Binds public and private bodies.

What this law does

Article 56 permits a Personal Data Controller to transfer personal data to a controller or processor outside Indonesia's legal territory, provided the recipient's country of domicile has a level of personal data protection equal to or higher than the Act's own standard. Later paragraphs of Article 56, which provide fallback mechanisms such as binding instruments or consent where the adequacy standard is not met, are not reproduced here. No data-localization mandate was found in the paragraphs read.

What it requires

Enforcement supervision

Law on Personal Data Protection, enforcement and private right to sue

Law No. 27 of 2022 on Personal Data Protection, Articles 12, 57-58government (.go.id) legal-documentation network mirror

In force since 17 October 2022. Binds public and private bodies.

What this law does

Article 12(1) gives a Personal Data Subject the right to sue and receive compensation for a violation, with the detailed procedure delegated to a Government Regulation not yet issued as of the date shown.

Article 57 subjects a violating controller to administrative sanctions, including written warning, temporary suspension of processing, deletion or destruction of data, and an administrative fine of up to 2 percent of annual revenue or income, with the fine-imposition procedure likewise delegated to a pending Government Regulation.

Enforcement authority sits with the not-yet-formally-established supervisory institution under Chapter IX, whose confirmed duties include compliance oversight, imposing sanctions, cross-border cooperation with peer regulators, and receiving complaints.

What it requires

Scraping law4 instruments, 4 in force

Research summary (241 words)

Indonesia has no scraping-specific statute, so general law governs each dimension separately. The Electronic Information and Transactions Law's unauthorised-access offence reaches a computer or system accessed without right regardless of whether any security measure is defeated, with a higher penalty tier reserved for access that breaches a security system, and no reported case has tested whether reading a public, unauthenticated page counts as access "without right".

The Copyright Law grants an exclusive reproduction right requiring the rights holder's permission, carries only a narrow research and criticism exception conditioned on not harming the creator's reasonable interest, and creates no text-and-data-mining exception for AI training.

The same Act protects a database as a copyrightable compilation, expressly excluding a database from the personal-use copying exception that otherwise permits single copies of published works, but creates no sui generis database right independent of that compilation-copyright theory.

The Personal Data Protection Law's lawful-basis requirement applies to personal data collected from a public Indonesian website on the same terms as any other collection, since its exhaustive list of lawful processing grounds carries no basis keyed to information the data subject has made public.

No Indonesian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule distinct from the copyright and personal-data findings above. No Indonesian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

Computer misuse

Electronic Information and Transactions Law, unauthorised access

Law No. 11 of 2008, Article 30 jo. Article 46, Electronic Information and Transactions LawMinistry of Communication and Digital Affairs' own legal-documentation network (JDIH Komdigi), official consolidated text

In force since 21 April 2008. Binds public and private bodies.

What this law does

Article 30 prohibits three escalating acts, each without right or unlawfully: paragraph (1) accessing another person's computer or electronic system by any means; paragraph (2) the same access with intent to obtain electronic information or documents; and paragraph (3) the same access carried out by violating, breaking through, exceeding, or breaching a security system, defined in the official elucidation as a system that restricts or prohibits computer access based on user classification and authorisation level.

Paragraphs (1) and (2) carry no textual requirement that any security measure be defeated, so a plain reading does not on its own resolve whether reading a public, unauthenticated page is access "without right"; this article has not been amended by the 2016 or 2024 amendments to the Law. Article 46 sets the corresponding criminal penalties.

What it requires

Personal data

Personal Data Protection Law, scraped personal data

Law No. 27 of 2022, Article 20, Personal Data Protection Lawgovernment (.go.id) legal-documentation network mirror

In force since 17 October 2022. Binds public and private bodies.

What this law does

Article 19 defines a Personal Data Controller to include every person, public body, and international organisation, and Article 20(1) requires a Controller to have a lawful basis before processing personal data.

Article 20(2) lists six lawful bases exhaustively: explicit consent for one or more stated purposes, performance of a contract to which the data subject is a party, compliance with the Controller's legal obligation, protection of the data subject's vital interest, performance of a public-interest or public-service task, or another legitimate interest balanced against the data subject's rights.

No basis in that list turns on the data having already been made public or being otherwise publicly accessible, so personal data collected from a public Indonesian website remains subject to the Act's ordinary lawful-basis, notice, and cross-border-transfer requirements on the same footing as personal data collected by any other means.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (718 words)

Indonesia's product-security and cyber-resilience posture for a private or government operator rests on Government Regulation No. 71 of 2019 on the Operation of Electronic Systems and Transactions (PP PSTE), signed by President Joko Widodo October 4, 2019, promulgated and effective October 10, 2019, and binding every Electronic System Operator (Penyelenggara Sistem Elektronik), whether a government body or a private business, without a sector or size gate.

Article 3 states the operator's general duty to run its Electronic System reliably and securely and to answer for its proper operation; Articles 23 and 24 operationalize that duty into a security-system requirement, secure the system's components and maintain procedures, means, and technical measures, such as antivirus, anti-spam, a firewall, intrusion detection or prevention, or an information security management system, to prevent and counter a threat or attack that causes disruption, failure, or loss; and Article 24(3) adds an incident-reporting duty triggered by a serious system failure or disruption caused by another party's act (an attack or intrusion), requiring the operator to secure the affected Electronic Information or Document and report immediately, at the first opportunity, to law enforcement and the relevant Ministry or Agency, with no numeric clock stated.

Articles 39 and 40, in the same Government Regulation's chapter on an Electronic Agent (a device within an Electronic System that carries out an action on Electronic Information automatically for a user, such as an automated transaction or e-commerce system), add a more specific security-control duty for that narrower class of operator: a standard operating procedure meeting six named principles, confidentiality, integrity, availability, authenticity, authorization, and non-repudiation, together with identity-authentication and authorization testing before completing a transaction.

A violation of Articles 23, 24, 31, 32, 39(2), or 40 can draw an administrative sanction from the Minister responsible for communications and informatics (today the Ministry of Communication and Digital Affairs), a written warning, an administrative fine of an amount this Government Regulation does not itself fix, temporary suspension, access termination, or removal from the operator registry, under Article 100; Article 100's own sanction list does not name Article 3 itself.

Indonesia has no enacted statute setting security requirements a connected device or software product must meet before or after it is placed on the market: the Directorate General of Resources and Postal and Informatics Devices (SDPPI) certification regime that reaches an IoT or telecommunications device tests radio-frequency and technical-standard compliance rather than cybersecurity, the same posture this profile has recorded for Japan's JC-STAR label and Singapore's Cybersecurity Labelling Scheme.

Ministerial Regulation No. 5 of 2020 on Private-Scope Electronic System Operators (Permenkominfo 5/2020) requires registration and a declaration that the registrant will meet information-security duties under prevailing law, but it states no security standard of its own beyond that cross-reference to PP PSTE, so it is not raised as a separate instrument here.

Presidential Regulation No. 82 of 2022 on the Protection of Vital Information Infrastructure (Perpres 82/2022) creates a critical-information-infrastructure regime, coordinated by the National Cyber and Crypto Agency (BSSN) and elaborated by BSSN's own 2023 regulations on identification, a protection framework, workforce capacity, and cybersecurity-maturity measurement, binding an operator the government individually designates as holding Vital Information Infrastructure across named strategic sectors (energy, transportation, tourism, finance, health, information and communication, food, defense, and others the President names); because that bound-party class turns on an individual government designation rather than on any activity this corpus's vocabulary can express, it is recorded here rather than raised against a declared activity, the same treatment this profile gives Japan's designated critical-infrastructure operators, Singapore's Cybersecurity Act classes, DORA's financial entities, and New York's Department of Financial Services Part 500 covered entities.

A dedicated Cybersecurity and Cyber Resilience Bill (RUU Keamanan dan Ketahanan Siber) has been under active deliberation in a House of Representatives working committee since June 2026, part of the 2026 National Legislation Program, but no enacted text exists, so it is named here as a pending development rather than treated as an instrument.

Indonesia's Personal Data Protection Law (UU No. 27/2022) carries its own data-security-safeguards clause and breach-notification duty, already this jurisdiction's privacy-topic finding rather than repeated here, and the Electronic Information and Transactions Law's unauthorized-access offense is already this jurisdiction's scraping-topic finding. No private right of action for the security duties described here was located; enforcement is administrative, through the Minister, under Article 100.

Security baseline statutes

Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty

Government Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40Official government regulation text, peraturan.bpk.go.id (State Gazette copy, Lembaran Negara RI 2019 No. 185)

In force since 10 October 2019. Binds public and private bodies.

What this law does

Every Electronic System Operator, government or private, must operate its Electronic System reliably and securely and is legally responsible for its proper operation. It must secure the system's components and have and run procedures and means to protect the system against disruption, failure, and loss. It must also provide a security system with prevention and countermeasure procedures against a threat or attack that causes such disruption, failure, or loss.

It must protect its users and the public from harm the system causes, and provide, train, and equip personnel responsible for securing the system's facilities and infrastructure. An operator running an Electronic Agent, an automated device carrying out actions on Electronic Information for a user, must additionally run a standard operating procedure meeting six security-control principles for user data and transactions. That operator must also test a transacting user's identity and authorization before completing a transaction.

What it requires

Vulnerability and incident reporting

Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting duty

Government Regulation No. 71 of 2019 (PP PSTE), Pasal 24(3)Official government regulation text, peraturan.bpk.go.id (State Gazette copy, Lembaran Negara RI 2019 No. 185)

In force since 10 October 2019. Binds public and private bodies.

What this law does

Where a system failure or disruption with a serious impact results from another party's act against its Electronic System, such as an attack or intrusion, the Electronic System Operator must secure the affected Electronic Information and/or Electronic Document and report the incident immediately, at the first opportunity, to law enforcement officials and the relevant Ministry or Agency.

The Government Regulation states no numeric clock for that report, only immediacy at the first opportunity, and binds the same general population of government and private Electronic System Operators as this jurisdiction's Article 23/24(1)-(2) security-system duty.

What it requires

Age gating law1 instrument, 1 in force

Research summary (116 words)

Indonesia's dedicated online child-protection instrument is Government Regulation No. 17 of 2025 on the Governance of Electronic System Operation in Child Protection, implementing Articles 16A(5) and 168(3) of the twice-amended Electronic Information and Transactions Law and in force since 27 March 2025.

It binds every Electronic System operator, public and private, that offers a product, service, or feature a child can use or access, sets five age bands from 3 to under 18, and requires disclosure of minimum age limits, an age-verification mechanism, and a complaint-reporting mechanism.

Ministerial oversight and administrative sanctions apply; the Regulation's specific sanction types are not described here, and detailed age-band and verification procedures are further delegated to an implementing Peraturan Menteri.

Age-appropriate design code

Government Regulation No. 17 of 2025 on Child Protection in Electronic Systems

Government Regulation No. 17 of 2025 on the Governance of Electronic System Operation in Child ProtectionDatabase Peraturan, Badan Pemeriksa Keuangan (BPK) legal database, official scanned text

In force since 27 March 2025. Binds public and private bodies.

What this law does

The Regulation applies to every Electronic System operator, distinguishing operators in the public sphere from those in the private sphere, and requires each to disclose the minimum age and age range able to use its Product, Service, or Feature, to provide a mechanism verifying whether a user is a child, and to provide a mechanism for reporting a Product, Service, or Feature that violates or risks violating a child's rights.

Article 20(2) sets five age bands: ages 3 to 5, 6 to 9, 10 to 12, 13 to 15, and 16 up to under 18. Article 21(1)(a) lets a child under 13 hold an account only on a Product, Service, or Feature specifically designed for a child's use, carrying a low risk profile, and only with parental consent.

Article 22 requires an operator performing age verification to protect the privacy and personal data of users, particularly children, to calibrate the verification mechanism's level of assurance to the risk the Product, Service, or Feature poses to a child's rights, to process verification data only for that purpose and delete it once the purpose is fulfilled (subject to any statutory retention duty), and to give users a mechanism to dispute or seek correction of an age determination.

Oversight of compliance sits with the Minister, who may monitor, investigate reports and complaints, and act on the results of an investigation; the specific administrative sanction types are set out later in the Regulation's own text, not described here.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (184 words)

Indonesia has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright Law's own exceptions are the only provisions reaching an aggregator's reproduction of news content.

Article 43(c) permits taking actual, current news, in whole or in part, from a news agency, broadcasting institution, newspaper, or similar source, provided the source is cited in full, without a headline-length or short-extract cap and without restricting the taking to the press industry itself.

Article 43(d) separately permits producing and disseminating copyrighted content through information and communication technology media where the activity is non-commercial, benefits the creator, or the creator has stated no objection to it. No reported Indonesian decision applies either exception to a systematic news aggregator as opposed to an individual taking or quoting a published work.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from these copyright exceptions was located. The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.