Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Indonesia receives hundreds of personal data protection complaints

Indonesia’s Directorate General of Digital Space Oversight (Komdigi) received 342 public complaints and handled 483 consultations between October 2024 and November 2025.

Komdigi, part of the Ministry of Communication and Digital, reported that 41% of these complaints involved personal data protection (PDP), while 89% of consultations were directly linked to PDP issues.

The agency audited 350 digital platforms—280 websites and 70 apps—finding 115 potential violations on websites and 24 on apps.

Web-based services showed a higher violation rate at 41%, compared to 34% for apps.

Komdigi also recorded 56 suspected PDP breaches during the monitoring period, with a spike in June and July 2025.

Most incidents were self-reported by electronic system operators, highlighting ongoing vulnerabilities.

The agency said draft regulations on personal data protection are nearing completion and stressed the need for stronger compliance and technical safeguards in digital services.

🔗 Source: DetikInet

🧠 Food for thought

Implications, context, and why it matters.

Indonesia’s Personal Data Protection (PDP) law leaves enforcement unclear

  • Indonesia enacted the Personal Data Protection Law (UU PDP) in 2022, yet nine required implementing rules remained unfinished by early 2025 1.
  • A Presidential Regulation (Perpres) with about 216 articles covers sanctions, breach reporting and cybersecurity standards 2. It remained in drafting and harmonization in February 2025 2.
  • Firms must report breaches within 3×24 hour (72-hour), with fines up to 2% of annual revenue 2. The Data Protection Supervisory Agency under the Ministry of Communication and Digital is still being built and will not be fully independent for about three years 2.
  • Penalties and oversight structures remain in flux. Outcomes are unclear for the 115 website violations and 24 app violations that the Directorate General of Digital Space Oversight (Komdigi) found, plus 56 suspected breaches during the monitoring period.

Privacy-tech vendors can pursue operators behind the 350 audited platforms and the wider PSE registry

  • The 350 audited platforms cover only a slice of Indonesia’s registered Electronic System Operators (PSE), which appear on the ministry’s public website 3.
  • Violations surfaced on 41% of websites, and breaches spiked in June to July 2025 4. These PSEs need stronger controls such as encryption and firewalls 4. They also need intrusion detection and a breach response plan 4.
  • Compliance software providers and cybersecurity consultants can pull contacts from the official PSE registry 1. Focus on e-commerce (retail), where studies find retailers suffer more breaches because customers switch easily. Fintech and other data-heavy fields also fit 1.
  • Indonesia ranks 8th worldwide for data breaches, with 94.22 million accounts leaked from 2020 to 2024 1.

Recent Komdigi developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.