Digital · 7 min read

Your site or app collects customer data — four duties that appear without you registering anything

Putting up a privacy policy page does not make your company compliant. And one wrong checkbox can wipe out your basis for using all your user data.

If your company runs an app, a transactional site or a subscription service, four duties attach to your product the moment people use it. Nobody sends you a notice. No single portal shows all four.

Here they are in the order most often missed, fastest consequence first.

1. Electronic system operator registration

The obligation arises before your system is used by users — not after the first user signs up, not after the first revenue.

Which means registering after launch puts you in breach from day one, even if no action has been taken.

The consequence of not registering is not a fine: access to your electronic system is cut off, with no written warning first. For a business whose entire revenue runs through an app, that is equivalent to ceasing operations.

Being registered is not the end either. Unreported changes to your data — changing domain, changing server location, changing business model — trigger a warning, temporary suspension, then blocking and revocation of the registration. Those three changes are exactly what technical teams do routinely without telling anyone.

One more thing: a foreign company with no Indonesian legal entity is still required to register if its service is offered in Indonesia, and its supporting documents must be translated by a sworn translator.

2. If you trade through an electronic system, there is a separate licence

Selling through an electronic system — as an online merchant, marketplace, social commerce, vehicle booking service or travel agent — has its own business licence. This is separate from the registration in point 1.

Sanctions include temporary blocking of the service and revocation of the business licence, not merely a fine.

Two things to know:

The rules in this area were recently replaced and the old terminology is gone. Advice, documents and templates still using the old term are out of date — a quick way to date the document in your hand.

3. Privacy policy — and the seven duties behind it

The transition period given by the personal data protection law ended on 17 October 2024. As of today that is more than a year and nine months ago.

Many companies are still waiting for implementing regulations before moving. Those regulations are indeed incomplete, but the core obligations do not wait for them — only some of the procedures do. A company that has not adapted is not waiting; legally it is already in breach.

And putting a privacy policy page on your site does not make your company compliant. At least seven other duties stand on their own:

  1. keeping evidence of user consent;
  2. maintaining a record of all processing activities;
  3. carrying out an impact assessment where risk is high;
  4. notifying a breach within three times twenty-four hours, to affected users and the authority;
  5. obtaining your written approval before a vendor uses a sub-vendor;
  6. appointing a data protection officer if the threshold is met;
  7. using the correct route for transferring data abroad.

If what you bought was only the policy text, those seven remain open. Worth knowing before you consider the matter closed.

What changed on 30 July 2025

The rule on who must appoint a data protection officer changed on 30 July 2025.

Previously the three criteria were read as needing to be met together, so almost no private company was caught. Now meeting a single criterion is enough.

As a result, companies processing personal financial data or children's data at scale, and platforms that regularly monitor user behaviour, now fall inside this duty.

The practical consequence: internal documents or advice produced before August 2025 are probably inaccurate on this point. If you were once told "not required", that conclusion needs re-reading.

On fines — and the honesty that has to come with it

The administrative fine is calculated on annual revenue, not profit, capped at two per cent. A loss-making company is still exposed.

But there is another side that honesty requires stating alongside it: the authority empowered to impose that fine has not been formed and its procedures are not yet issued, so the collection machinery is not running. The exposure is real and continuing; the collection is not.

That institutional gap is often read as no enforcement. That reading is wrong. What still runs today:

The institutional gap delays one route, not all of them.

Two things almost always missed

A vendor's mistake is still your responsibility. Processing carried out by a party you appoint sits under your responsibility, and the vendor must obtain your written approval before involving a sub-vendor. That last clause is almost never present in the standard agreements of foreign service providers — it is usually inverted into a vendor right to change sub-vendors on notice alone.

Almost every Indonesian company transfers data abroad without realising it: cloud computing with servers overseas, marketing email services, advertising platforms, and application error monitors. All of those are cross-border data transfers subject to their own rules.

Two important notes on that transfer. The easiest route in theory — sending to a country with an equivalent level of protection — cannot yet be used, because the country list has not been issued. And the route of asking for user consent is fragile, because consent can be withdrawn at any time.

A privacy policy cannot be changed on an "effective when posted" model

Notice to users must precede the change taking effect, not follow it.

The clause common in foreign templates — changes take effect on publication, and users are deemed to agree by continuing to use the service — does not meet this. The consequence is worth accepting early: your ability to change policy quickly is limited.

A perfect text still is not enough if your product has no buttons for it

Providing a way for users to request deletion, a recorded request channel, the ability to export data, and the ability to keep consent evidence per version of the text is work inside the application, not inside the document.

If your product team is not doing it, even the best document promises something the system itself cannot deliver.

4. Terms and conditions — and the clauses that are actually prohibited

A number of clauses commonly used in apps and sites are prohibited by law. The consequence is not merely that they do not apply: they are void by operation of law, treated as never having existed, with no court ruling needed first.

The two most often problematic:

Both need rewriting, not softening.

The exposure is not only civil. Consumer protection law provides for imprisonment of up to five years or a fine of up to two billion rupiah, and prosecution can be directed at company directors, not only the company.

And claims usually do not arrive through slow, expensive courts but through the consumer dispute settlement body — cheap, fast, and requiring no lawyer. The threshold for being sued is far lower than most people assume.

Three more things to check:

One more if your product may be reached by children: stating a minimum age is not enough. What is required is an age verification and parental consent mechanism.

The most expensive mistake: one checkbox for both

Combining consent to the privacy policy with acceptance of the terms and conditions in a single checkbox is the mistake we find most often, and its consequence is far larger than people expect.

Consent that cannot be clearly distinguished is void by operation of law. If that happens, the data you have collected changes status to data obtained without consent, and users are entitled to demand its deletion.

What is at stake here is not a fine. What is at stake is your user database — usually the most valuable asset a digital company has, and the only one that cannot be bought back.

One honest word about the uncertainty

The personal data protection law has been in force since October 2022, but to date the Indonesian courts have barely tested it. Our search of the decision database found only a dozen or so cases mentioning it, all at first instance and appeal, none reaching cassation.

Two consequences matter. First, anyone stating with certainty how a court will decide a personal data dispute is guessing — including us. What can be offered is a careful reading of the statute, not a map of precedent. Second, precisely because the boundaries are untested, the conservative choice is almost always cheaper than betting on a loose interpretation.

What you can do yourself, this weekend

  1. Open your account registration page and count the checkboxes. Are privacy policy consent and terms acceptance in two separate boxes? If it is one box, fix that first — and your product team can fix it in a day.
  2. List every third-party service that touches your user data. Cloud, marketing email, analytics, advertising, error monitoring, messaging. That list is your cross-border transfer list, and it is almost always longer than expected.
  3. Check whether an Indonesian text exists, not only English.
  4. Search for the sentence "we may change these terms at any time and changes take effect when published". If it is there, it is a problem in two places at once: in the terms, and in the privacy policy.
  5. Write a one-page breach procedure now, before an incident. Four things is enough: who decides this is a breach, from what hour the three-times-twenty-four-hour clock starts, through what channel users are told, and who files with the authority. A procedure that has not settled all four will always be late.
  6. Create one processing activity record. One row per data type: what is collected, what for, stored where, for how long, who can see it. This is a duty in its own right, and it can be as simple as a one-page table.
  7. Make sure consent evidence is stored per version of the text, not merely "user agreed".
  8. If your technical team plans to change domain, change server provider, or change business model — note that all three are reportable changes, and mark who is responsible for reporting them.

Those eight steps need no lawyer. What needs legal judgement is establishing the processing basis for each activity, assessing risk levels, assessing whether the data protection officer threshold is met, and drafting vendor agreement clauses — that is interpretation, not form-filling.

Related service

Privacy Policy & Personal Data Protection Compliance Toolkit

Kebijakan Privasi yang berdiri di atas dasar pemrosesan yang sah — lengkap dengan catatan, prosedur, dan bukti yang diminta undang-undang di belakangnya.

See the service

Written 2026-07-30. Rules change — if you are reading this long after that date, confirm before you act on it.