Compliance guide

PP 71/2019 (PSTE) Compliance Guide

Government Regulation No. 71 of 2019 sets baseline obligations for every Electronic System Operator in Indonesia. Claro helps you strengthen the security and personal-data controls that depend on your people.

Regulator
Government of Indonesia (Kominfo/Komdigi)
Applies to
Electronic System Operators (PSE), public and private scope

Overview

Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions, known as PSTE (Penyelenggaraan Sistem dan Transaksi Elektronik), has been in force since October 2019. It sets the core obligations for any Electronic System Operator (PSE) in Indonesia: registration with the Minister, reliable and secure operation of electronic systems, and the protection of personal data. In effect, it is the baseline rulebook for running digital services in the country.

PP 71/2019 distinguishes between public-scope PSE and private-scope PSE, with registration and oversight administered by Kominfo, now Komdigi. Its reach is broad, covering public agencies as well as private businesses including banks, fintechs, e-commerce platforms, and other regulated entities. Many of these organizations layer sector-specific rules, such as financial-services or health regulations, on top of the PSTE baseline, so the regulation is best understood as a foundation that other obligations build upon.

Security and personal-data protection sit at the heart of PP 71/2019. Operators are expected to run their systems reliably and safely, safeguard the personal data they process, and be ready to respond when incidents occur. Because unauthorized access frequently begins with phishing and stolen credentials, the human layer, how your staff recognize and report deceptive messages, has a direct bearing on whether these security and data-protection duties are met in practice. Regulators and boards increasingly expect operators to show not just that policies exist, but that staff behaviour has been tested and is improving. A phishing simulation and reporting program is one of the most tangible ways to produce that proof.

This page is general information to help you plan the human-risk side of PSTE readiness; it is not legal advice, and it does not cover registration mechanics or the full scope of the regulation. Requirements are administered by Komdigi and interact with other laws, including Indonesia's personal data protection regime, so confirm your specific obligations with official guidance and qualified counsel. Claro supports the awareness, phishing-resilience, and evidence controls that underpin secure operation, but a tool alone does not make an organization compliant.

What the rule expects

Register as an Electronic System Operator (PSE)

PP 71/2019 requires PSE to register with the Minister, with distinct treatment for public-scope and private-scope operators. Registration is administered by Komdigi and is the entry point to the wider obligations that follow.

Operate electronic systems reliably and securely

Operators must run their systems in a reliable, safe, and responsible manner. In practice this means maintaining technical and organizational safeguards, including controls that reduce the chance of human-driven compromise such as phishing.

Protect the personal data you process

The regulation obliges PSE to safeguard personal data throughout its lifecycle and to respect the rights of data subjects. Credential theft and social engineering are common routes to data exposure, so protecting people is inseparable from protecting data.

Apply appropriate security controls and risk management

PSE are expected to manage security risk proportionately to the systems and data they handle. Awareness of, and resilience to, phishing and social engineering is a recognized part of a sound control environment.

Prepare for and respond to security incidents

Operators should be able to detect, respond to, and recover from incidents affecting their electronic systems. Fast internal reporting of suspicious messages is a practical early-warning mechanism that supports incident response.

Maintain accountability and records of your safeguards

Demonstrating that safeguards exist and function is central to responsible operation and any regulatory engagement. Organizations benefit from records that show awareness activity, simulation results, and how incidents were handled.

Respect data-handling and residency expectations

PSTE interacts with expectations about how and where certain data is processed and stored. Systems that handle employee data, including awareness platforms, should offer deployment options consistent with your data-handling posture.

How Claro helps you comply

  • Test phishing resilience with realistic simulations

    Claro runs bilingual phishing simulations with scheduling, throttling, and per-recipient tracking of opens, clicks, submissions, and reports. This measures and improves how your workforce resists the social engineering that so often precedes unauthorized access and data exposure.

  • Strengthen protection of personal data through people

    Because credential theft is a leading cause of data incidents, reducing successful phishing directly supports the personal-data obligations under PSTE. Claro's simulations and training lower the odds that a deceptive message turns into unauthorized access to the data you hold.

  • Just-in-time awareness and role-based training

    When a user fails a simulation, Claro delivers an instant awareness page and auto-enrols them in relevant micro-modules. Bilingual learning paths and assignment rules keep security awareness continuous across public-facing and back-office roles alike.

  • Shorten detection with a built-in reporting loop

    The Claro phish-report button (Outlook add-in and Gmail extension) lets staff flag suspicious emails in one click. Reports feed a central loop that shortens detection time and supports the incident-response readiness PSTE expects of operators.

  • Evidence packages for accountability

    Claro's compliance module maps control coverage and produces evidence packages (ZIP bundles of PDFs and CSVs) plus Claro-style reports. This gives you defensible records of awareness activity and human-risk reduction to support accountability and regulatory engagement.

  • Secure architecture and deployment choices

    Claro provides per-tenant data isolation, AES-256-GCM encryption of personal data at rest, and detailed audit logs. On-premise or SaaS deployment lets you align the platform with your data-handling and residency posture under PSTE.

Frequently asked questions

  • It is Indonesia's Government Regulation No. 71 of 2019 on the implementation of electronic systems and transactions, known as PSTE. It sets baseline obligations for Electronic System Operators: register with the Minister, run systems reliably and securely, and protect personal data.

This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.

Build defensible security awareness evidence

Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.

Request a demo