Digital · 7 min read
Putting up a privacy policy page does not make your company compliant. And one wrong checkbox can wipe out your basis for using all your user data.
If your company runs an app, a transactional site or a subscription service, four duties attach to your product the moment people use it. Nobody sends you a notice. No single portal shows all four.
Here they are in the order most often missed, fastest consequence first.
The obligation arises before your system is used by users — not after the first user signs up, not after the first revenue.
Which means registering after launch puts you in breach from day one, even if no action has been taken.
The consequence of not registering is not a fine: access to your electronic system is cut off, with no written warning first. For a business whose entire revenue runs through an app, that is equivalent to ceasing operations.
Being registered is not the end either. Unreported changes to your data — changing domain, changing server location, changing business model — trigger a warning, temporary suspension, then blocking and revocation of the registration. Those three changes are exactly what technical teams do routinely without telling anyone.
One more thing: a foreign company with no Indonesian legal entity is still required to register if its service is offered in Indonesia, and its supporting documents must be translated by a sworn translator.
Selling through an electronic system — as an online merchant, marketplace, social commerce, vehicle booking service or travel agent — has its own business licence. This is separate from the registration in point 1.
Sanctions include temporary blocking of the service and revocation of the business licence, not merely a fine.
Two things to know:
The rules in this area were recently replaced and the old terminology is gone. Advice, documents and templates still using the old term are out of date — a quick way to date the document in your hand.
The transition period given by the personal data protection law ended on 17 October 2024. As of today that is more than a year and nine months ago.
Many companies are still waiting for implementing regulations before moving. Those regulations are indeed incomplete, but the core obligations do not wait for them — only some of the procedures do. A company that has not adapted is not waiting; legally it is already in breach.
And putting a privacy policy page on your site does not make your company compliant. At least seven other duties stand on their own:
If what you bought was only the policy text, those seven remain open. Worth knowing before you consider the matter closed.
The rule on who must appoint a data protection officer changed on 30 July 2025.
Previously the three criteria were read as needing to be met together, so almost no private company was caught. Now meeting a single criterion is enough.
As a result, companies processing personal financial data or children's data at scale, and platforms that regularly monitor user behaviour, now fall inside this duty.
The practical consequence: internal documents or advice produced before August 2025 are probably inaccurate on this point. If you were once told "not required", that conclusion needs re-reading.
The administrative fine is calculated on annual revenue, not profit, capped at two per cent. A loss-making company is still exposed.
But there is another side that honesty requires stating alongside it: the authority empowered to impose that fine has not been formed and its procedures are not yet issued, so the collection machinery is not running. The exposure is real and continuing; the collection is not.
That institutional gap is often read as no enforcement. That reading is wrong. What still runs today:
The institutional gap delays one route, not all of them.
A vendor's mistake is still your responsibility. Processing carried out by a party you appoint sits under your responsibility, and the vendor must obtain your written approval before involving a sub-vendor. That last clause is almost never present in the standard agreements of foreign service providers — it is usually inverted into a vendor right to change sub-vendors on notice alone.
Almost every Indonesian company transfers data abroad without realising it: cloud computing with servers overseas, marketing email services, advertising platforms, and application error monitors. All of those are cross-border data transfers subject to their own rules.
Two important notes on that transfer. The easiest route in theory — sending to a country with an equivalent level of protection — cannot yet be used, because the country list has not been issued. And the route of asking for user consent is fragile, because consent can be withdrawn at any time.
Notice to users must precede the change taking effect, not follow it.
The clause common in foreign templates — changes take effect on publication, and users are deemed to agree by continuing to use the service — does not meet this. The consequence is worth accepting early: your ability to change policy quickly is limited.
Providing a way for users to request deletion, a recorded request channel, the ability to export data, and the ability to keep consent evidence per version of the text is work inside the application, not inside the document.
If your product team is not doing it, even the best document promises something the system itself cannot deliver.
A number of clauses commonly used in apps and sites are prohibited by law. The consequence is not merely that they do not apply: they are void by operation of law, treated as never having existed, with no court ruling needed first.
The two most often problematic:
Both need rewriting, not softening.
The exposure is not only civil. Consumer protection law provides for imprisonment of up to five years or a fine of up to two billion rupiah, and prosecution can be directed at company directors, not only the company.
And claims usually do not arrive through slow, expensive courts but through the consumer dispute settlement body — cheap, fast, and requiring no lawyer. The threshold for being sued is far lower than most people assume.
Three more things to check:
One more if your product may be reached by children: stating a minimum age is not enough. What is required is an age verification and parental consent mechanism.
Combining consent to the privacy policy with acceptance of the terms and conditions in a single checkbox is the mistake we find most often, and its consequence is far larger than people expect.
Consent that cannot be clearly distinguished is void by operation of law. If that happens, the data you have collected changes status to data obtained without consent, and users are entitled to demand its deletion.
What is at stake here is not a fine. What is at stake is your user database — usually the most valuable asset a digital company has, and the only one that cannot be bought back.
The personal data protection law has been in force since October 2022, but to date the Indonesian courts have barely tested it. Our search of the decision database found only a dozen or so cases mentioning it, all at first instance and appeal, none reaching cassation.
Two consequences matter. First, anyone stating with certainty how a court will decide a personal data dispute is guessing — including us. What can be offered is a careful reading of the statute, not a map of precedent. Second, precisely because the boundaries are untested, the conservative choice is almost always cheaper than betting on a loose interpretation.
Those eight steps need no lawyer. What needs legal judgement is establishing the processing basis for each activity, assessing risk levels, assessing whether the data protection officer threshold is met, and drafting vendor agreement clauses — that is interpretation, not form-filling.
Related service
Kebijakan Privasi yang berdiri di atas dasar pemrosesan yang sah — lengkap dengan catatan, prosedur, dan bukti yang diminta undang-undang di belakangnya.
See the serviceWritten 2026-07-30. Rules change — if you are reading this long after that date, confirm before you act on it.