Doing Business In..._2026

INDONESIA Law and Practice Contributed by: Agus Ahadi Deradjat (Agung), Gustaaf Reerink, Adri Dharma, Karina Widyaputri and Ilma Sulistyani, ABNR Counsellors at Law

• pre-existing regulations that remain valid insofar as they do not conflict with the PDP Law; • specifically for children’s personal data, in regula - tions regarding child protection; and • sector-specific laws and regulations, such as those governing telecommunications, electronic transac - tions, medical records, and financial services. 8.2 Geographical Scope The PDP Law has a notable extra-territorial effect, extending its reach beyond the country’s borders. As stipulated in Article 2, the law applies to all legal acts involving personal data processing that are con - ducted: • within the jurisdiction of Indonesia; and • outside the jurisdiction of Indonesia, if such acts result in legal consequences: (a) within Indonesia; and/or (b) for data subjects who are Indonesian citizens located abroad. This provision ensures that foreign-based data con - trollers – including individuals, public agencies, and international organisations – are subject to the PDP Law if their activities affect Indonesian citizens or have legal implications within Indonesia. Consequently, a foreign company without a legal pres - ence in Indonesia that provides services to Indonesian users must still comply with the PDP Law. If it fails to process the personal data of those users in accord - ance with the law’s requirements, it may be subject to enforcement actions and sanctions, despite operating from outside Indonesia. 8.3 Role and Authority of the Data Protection Agency At present, the enforcement of PDP Law is overseen by the Directorate General of Digital Space Supervi - sion (DG) under MOCD. While the PDP Law mandates the establishment of an independent Data Protection Authority (DPA) – tasked with regulatory, supervisory, and enforcement respon - sibilities – this authority has not yet been formally con - stituted.

In the interim, pursuant to MOCD Regulation No 1 of 2025 on Organisation and Work Procedures, the DG continues to serve as the competent authority for personal data protection matters. Its responsibilities include: • formulating and implementing policies related to digital space supervision and personal data protec - tion; • executing those policies; • monitoring, analysing, evaluating, and reporting on digital space and data protection activities; • managing internal administration of the DG; and • carrying out additional functions as assigned by MOCD. The MOCD has publicly stated its intention to expe - dite the formation of the DPA, signalling that its estab - lishment remains a high priority for the government. However, as of mid-2026, no definitive timeline has been announced for the establishment of the DPA. 9. Looking Forward 9.1 Upcoming Legal Reforms Updates to the KBLI and Business Licensing System On 27 March 2026, the Ministry of Investment and Downstream Industry/Head of BKPM, the MOL, and the Central Statistics Agency (BPS) issued a Joint Circular Letter to facilitate the implementation of the 2025 Indonesian Standard Business Field Classifica - tion (KBLI 2025) within the risk-based licensing frame - work. The Joint Circular Letter follows the issuance of BPS Regulation No 7 of 2025, which introduces KBLI 2025 and replaces the previous KBLI 2020 classification. The updated framework includes, among others, the consolidation and splitting of various business clas - sification codes. Under the new regime: • Existing licences and approvals issued prior to the implementation of KBLI 2025 remain valid.

485 CHAMBERS.COM

Powered by