UU PDP compliance
The cost of UU PDP non-compliance: fines, sanctions, and business risk
In short
UU PDP allows administrative sanctions up to 2% of annual revenue tied to the violation and criminal penalties up to 6 years imprisonment. Full breakdown of non-compliance costs for Indonesian companies.
Many Indonesian companies still treat UU PDP as a regulation for "later" or assume "nobody has been fined yet." Both assumptions are now incorrect. The transition period ended in October 2024, enforcement infrastructure is being built, and the sanctions are designed to be felt, not merely symbolic.
This page details the sanctions that can be imposed, how they are calculated, and the indirect costs that are often overlooked in risk assessments.
UU PDP sanction structure
UU PDP recognises three categories of sanction: administrative, civil, and criminal. All three can apply simultaneously for a single incident.
| Sanction type | Provision | Authority |
|---|---|---|
| Administrative sanctions | Written warning, temporary processing suspension, data deletion, administrative fine up to 2% of annual revenue tied to the violation | Personal Data Protection Authority / BSSN |
| Civil lawsuit | Compensation to affected data subjects for material and immaterial losses resulting from the violation | Courts |
| Criminal: Article 67 | Unauthorised use of personal data: maximum 4 years imprisonment and/or fine up to IDR 4 billion | Police / Prosecutor |
| Criminal: Article 68 | Unauthorised disclosure of specific data (health, financial, biometric): maximum 5 years imprisonment and/or fine up to IDR 5 billion | Police / Prosecutor |
| Criminal: Article 69 | Falsification of personal data for own or third-party benefit: maximum 6 years imprisonment and/or fine up to IDR 6 billion | Police / Prosecutor |
How the administrative fine is calculated
2%
Ceiling on the administrative fine, applied to revenue tied to the violation (Article 57)
IDR 6B
Maximum criminal fine (Article 69)
6 years
Maximum criminal imprisonment (Article 69)
Article 57 paragraph 3 sets the administrative fine at up to 2 percent of the annual income or annual revenue tied to the violation. That last qualifier is the part most often dropped. The 2 percent ceiling attaches to the revenue associated with the processing activity that fell short, not to the company's total turnover. A company with several business lines is therefore not automatically exposed to 2 percent of its consolidated revenue, and any rupiah figure calculated from whole-company revenue overstates the real exposure.
How the violation variable is to be measured has not been settled. The implementing regulation that would specify the calculation method has not been issued, the Personal Data Protection Authority is still being established, and as at this update there are no reported cases of a UU PDP administrative fine actually being imposed. Any rupiah figure circulating as the "maximum UU PDP fine" is therefore an estimate rather than the product of an applied rule.
What is settled is the shape and order of the sanctions. A fine is not the first step. Article 57 paragraph 2 sets out a ladder that begins with a written warning, then temporary suspension of processing activities, then erasure or destruction of personal data, and only then an administrative fine. The 2 percent figure is also a ceiling rather than a flat rate, so the degree of intent, the impact on data subjects, and mitigation efforts still determine the final amount.
Indirect costs that are often overlooked
Regulatory fines are the easy-to-calculate part. Indirect costs are frequently larger.
Litigation and legal fees
A single civil lawsuit from hundreds or thousands of affected data subjects can generate litigation costs far exceeding the regulatory fine. The mechanism for collective claims under UU PDP is untested but exists.
Temporary operational suspension
Regulations allow temporary suspension of data processing activities during investigation. For companies whose operations depend on customer data processing, this can mean complete service interruption.
Incident notification costs
You must notify all affected data subjects individually. For a database of 100,000 customers, the operational cost of notification alone can reach hundreds of millions of rupiah.
Reputational damage and client loss
Industry surveys show 60-70% of consumers reconsider their relationship with an organisation that experiences a public data breach. For B2B, the impact per client is far larger.
Violations most likely to trigger sanctions
Risk comparison: compliant vs non-compliant
| Without a UU PDP compliance programme | With an active compliance programme | |
|---|---|---|
| Regulatory fine exposure | Up to 2% of annual revenue tied to the violation, per incident | Substantially lower due to good faith evidence |
| Criminal risk for executives | Articles 67-69 can target individuals, not just corporations | Compliance documentation protects individuals from personal liability |
| Incident response speed | No playbook, the 3x24 hour notification deadline is difficult to meet | Playbooks and templates ready, deadline achievable |
| Position in government and corporate tenders | Increasingly, tenders require evidence of UU PDP compliance | Certification and documentation ready for proposals |
| Relationship with regulators | Investigation begins from a defensive position | Evidence of proactive compliance effort influences regulator assessment |
The most practical first step
For most companies, the most efficient starting point is a UU PDP gap assessment: a short audit that identifies where you stand against the main obligations and which priorities need to be addressed first.
Alpha Code provides this assessment as part of its DPO-as-a-Service offering, including a prioritised report ready for presentation to a board of directors or audit committee.
References
- 1.Law Number 27 of 2022 on Personal Data Protection, Article 57 (administrative sanctions) and Articles 67 to 69 (criminal provisions)
- 2.Law Number 27 of 2022, JDIH Ministry of Communication and Digital Affairs
- 3.UU PDP bilingual text (Indonesian/English), ABNR Counsellors at Law
- 4.Sanctions and compliance with Indonesia's Personal Data Protection Law (UU PDP), Schinder Law Firm
Reviewed by Tyas Suci, ISMS & Compliance Consultant
Frequently asked questions
Article 57 sets the administrative fine at up to 2% of the annual income or annual revenue tied to the violation, not 2% of the company's total turnover. For criminal violations such as unauthorised use of personal data, maximum imprisonment is 5 years and criminal fines up to IDR 5 billion per article.
Related
Solutions
From the blog
Our services
Ready to strengthen your security posture?
Talk to our Jakarta-based team about your requirements.
Jakarta-based team. We reply within one business day.