Skip to main content

UU PDP compliance

The cost of UU PDP non-compliance: fines, sanctions, and business risk

In short

UU PDP allows administrative sanctions up to 2% of annual revenue tied to the violation and criminal penalties up to 6 years imprisonment. Full breakdown of non-compliance costs for Indonesian companies.

Compliance solutions

Many Indonesian companies still treat UU PDP as a regulation for "later" or assume "nobody has been fined yet." Both assumptions are now incorrect. The transition period ended in October 2024, enforcement infrastructure is being built, and the sanctions are designed to be felt, not merely symbolic.

This page details the sanctions that can be imposed, how they are calculated, and the indirect costs that are often overlooked in risk assessments.

UU PDP sanction structure

UU PDP recognises three categories of sanction: administrative, civil, and criminal. All three can apply simultaneously for a single incident.

Sanction typeProvisionAuthority
Administrative sanctionsWritten warning, temporary processing suspension, data deletion, administrative fine up to 2% of annual revenue tied to the violationPersonal Data Protection Authority / BSSN
Civil lawsuitCompensation to affected data subjects for material and immaterial losses resulting from the violationCourts
Criminal: Article 67Unauthorised use of personal data: maximum 4 years imprisonment and/or fine up to IDR 4 billionPolice / Prosecutor
Criminal: Article 68Unauthorised disclosure of specific data (health, financial, biometric): maximum 5 years imprisonment and/or fine up to IDR 5 billionPolice / Prosecutor
Criminal: Article 69Falsification of personal data for own or third-party benefit: maximum 6 years imprisonment and/or fine up to IDR 6 billionPolice / Prosecutor

How the administrative fine is calculated

2%

Ceiling on the administrative fine, applied to revenue tied to the violation (Article 57)

IDR 6B

Maximum criminal fine (Article 69)

6 years

Maximum criminal imprisonment (Article 69)

Article 57 paragraph 3 sets the administrative fine at up to 2 percent of the annual income or annual revenue tied to the violation. That last qualifier is the part most often dropped. The 2 percent ceiling attaches to the revenue associated with the processing activity that fell short, not to the company's total turnover. A company with several business lines is therefore not automatically exposed to 2 percent of its consolidated revenue, and any rupiah figure calculated from whole-company revenue overstates the real exposure.

How the violation variable is to be measured has not been settled. The implementing regulation that would specify the calculation method has not been issued, the Personal Data Protection Authority is still being established, and as at this update there are no reported cases of a UU PDP administrative fine actually being imposed. Any rupiah figure circulating as the "maximum UU PDP fine" is therefore an estimate rather than the product of an applied rule.

What is settled is the shape and order of the sanctions. A fine is not the first step. Article 57 paragraph 2 sets out a ladder that begins with a written warning, then temporary suspension of processing activities, then erasure or destruction of personal data, and only then an administrative fine. The 2 percent figure is also a ceiling rather than a flat rate, so the degree of intent, the impact on data subjects, and mitigation efforts still determine the final amount.

Indirect costs that are often overlooked

Regulatory fines are the easy-to-calculate part. Indirect costs are frequently larger.

Litigation and legal fees

A single civil lawsuit from hundreds or thousands of affected data subjects can generate litigation costs far exceeding the regulatory fine. The mechanism for collective claims under UU PDP is untested but exists.

Temporary operational suspension

Regulations allow temporary suspension of data processing activities during investigation. For companies whose operations depend on customer data processing, this can mean complete service interruption.

Incident notification costs

You must notify all affected data subjects individually. For a database of 100,000 customers, the operational cost of notification alone can reach hundreds of millions of rupiah.

Reputational damage and client loss

Industry surveys show 60-70% of consumers reconsider their relationship with an organisation that experiences a public data breach. For B2B, the impact per client is far larger.

Violations most likely to trigger sanctions

No valid consent mechanism for data collectionData breach without written notice to data subjects and the supervisory authority within 3x24 hours (Article 46)No DPO appointed despite being requiredCross-border data transfers without adequate safeguardsData retained longer than necessary without a clear legal basisFailure to respond to data subject rights requests within 30 days

Risk comparison: compliant vs non-compliant

 Without a UU PDP compliance programmeWith an active compliance programme
Regulatory fine exposureUp to 2% of annual revenue tied to the violation, per incidentSubstantially lower due to good faith evidence
Criminal risk for executivesArticles 67-69 can target individuals, not just corporationsCompliance documentation protects individuals from personal liability
Incident response speedNo playbook, the 3x24 hour notification deadline is difficult to meetPlaybooks and templates ready, deadline achievable
Position in government and corporate tendersIncreasingly, tenders require evidence of UU PDP complianceCertification and documentation ready for proposals
Relationship with regulatorsInvestigation begins from a defensive positionEvidence of proactive compliance effort influences regulator assessment

The most practical first step

For most companies, the most efficient starting point is a UU PDP gap assessment: a short audit that identifies where you stand against the main obligations and which priorities need to be addressed first.

Alpha Code provides this assessment as part of its DPO-as-a-Service offering, including a prioritised report ready for presentation to a board of directors or audit committee.

References

  1. 1.Law Number 27 of 2022 on Personal Data Protection, Article 57 (administrative sanctions) and Articles 67 to 69 (criminal provisions)
  2. 2.Law Number 27 of 2022, JDIH Ministry of Communication and Digital Affairs
  3. 3.UU PDP bilingual text (Indonesian/English), ABNR Counsellors at Law
  4. 4.Sanctions and compliance with Indonesia's Personal Data Protection Law (UU PDP), Schinder Law Firm

Reviewed by Tyas Suci, ISMS & Compliance Consultant

Frequently asked questions

Article 57 sets the administrative fine at up to 2% of the annual income or annual revenue tied to the violation, not 2% of the company's total turnover. For criminal violations such as unauthorised use of personal data, maximum imprisonment is 5 years and criminal fines up to IDR 5 billion per article.

Related

Ready to strengthen your security posture?

Talk to our Jakarta-based team about your requirements.

Jakarta-based team. We reply within one business day.