Three layers of consequence, not one
Discussions of UU PDP penalties usually collapse into a single number, most often the 2 percent figure. That is misleading. Law 27/2022 creates three distinct layers of consequence, and they operate independently: administrative sanctions imposed by the supervisory authority, civil liability to data subjects who suffered loss, and criminal provisions that reach individuals as well as corporations.
An organization can face more than one layer for the same incident. An administrative fine does not extinguish a data subject's right to sue for damages, and neither prevents criminal process where the conduct meets the threshold. Planning for only the administrative layer understates the real exposure.
The two-year transition period following enactment in October 2022 has now ended, so these obligations apply in full. This guide is written for security and compliance leaders who need to size the risk. It is not legal advice, and your sector may add obligations on top: financial institutions also answer to OJK, and incidents involving electronic systems can involve BSSN.
Administrative sanctions and the 2 percent fine
Administrative sanctions are the layer most organizations will encounter first. They escalate: a written warning, temporary suspension of personal data processing activity, an order to delete or destroy personal data that was processed unlawfully, and an administrative fine.
The administrative fine is capped at 2 percent of annual revenue or annual receipts. Two details matter more than the headline percentage. First, the cap is calculated against revenue, not profit, so it does not scale down for a business having a bad year. Second, the suspension and deletion sanctions can be more disruptive than the fine itself. An order to suspend processing can halt customer onboarding; an order to delete unlawfully processed data can remove records a business depends on.
For a mid-sized Indonesian bank or fintech, the operational sanctions are usually the sharper risk. Model them alongside the fine rather than treating the percentage as the whole story.
Criminal provisions under Article 67
Article 67 sets out the core criminal offences. Unlawfully obtaining or collecting personal data that does not belong to you, with the intent of benefiting from it, carries imprisonment of up to five years and a fine of up to IDR 5 billion. Related provisions address unlawfully disclosing and unlawfully using personal data that is not your own.
The threshold here is unlawful conduct with intent, not a mere compliance gap. A configuration error that exposes a database is unlikely to be prosecuted under Article 67. An employee who exports a customer list and sells it is squarely within scope, and so is an outsider who phishes credentials to reach that data.
This is the provision that connects data protection to workforce behaviour most directly. The majority of unlawful access to personal data begins with a person, either an insider acting deliberately or a member of staff deceived into handing over access.
How corporations are treated differently
Where an offence is committed by or on behalf of a corporation, the law reaches the corporate entity, not only the individuals involved. Additional penalties available against corporations include confiscation of profits or assets obtained from the offence, freezing of some or all of the corporation's business activity, and in the most serious cases dissolution of the corporation.
Freezing of business activity deserves attention from anyone building a board-level risk case. For a regulated financial institution, a freeze on part of the business is an existential operational event, well beyond the financial impact of any fine.
The practical implication is that UU PDP exposure belongs on the enterprise risk register, not only in the compliance function's own tracker. Boards of Indonesian financial institutions are already required to demonstrate oversight of technology risk, and personal data handling sits inside that remit.
What actually triggers enforcement
Regulators rarely discover a breach unaided. Enforcement attention typically follows one of three routes: a data subject complaint, a breach that becomes public, or a mandatory notification the organization files itself. UU PDP requires notification of a failure to protect personal data within 3x24 hours of becoming aware of it, to both the affected data subjects and the authority.
That notification requirement creates a specific operational risk. An organization that detects an incident late, or cannot reconstruct what happened, will miss the window or file an incomplete notification. Both are visible failures that invite closer scrutiny of everything else.
The organizations that fare best are not the ones with the thickest policy binder. They are the ones that can show, on request, who had access to what, that staff were trained on handling personal data, and that the incident was detected and escalated on a timeline that stands up.
Reducing exposure: the controls that matter
Three control areas do most of the work in reducing UU PDP exposure. Access discipline, so that fewer people can reach personal data and access is removed when roles change. Workforce awareness, so that staff recognise the social engineering that precedes most unlawful access. And evidence, so that both of the above can be demonstrated rather than asserted.
Awareness is a compliance control here, not a nice-to-have. The law asks for security measures appropriate to the risk, and the dominant risk to personal data in Indonesian organizations is a person being deceived. Phishing simulation, measured over time and broken down by department, produces exactly the evidence a supervisory authority or an auditor will ask for.
Claro runs bilingual phishing simulation and awareness training built for Indonesian organizations, with per-user risk scoring and exportable evidence mapped to UU PDP, OJK and ISO 27001 expectations. Deployment can be on-premise where data residency requirements make that necessary.
Key takeaways
- UU PDP creates three independent layers of consequence: administrative, civil and criminal. An administrative fine does not close off the other two.
- The administrative fine is capped at 2 percent of annual revenue, but suspension of processing and mandatory deletion are often more operationally damaging.
- Article 67 criminal provisions carry up to five years imprisonment and IDR 5 billion in fines for unlawfully obtaining personal data with intent to benefit.
- Corporations face additional penalties including confiscation of profits, freezing of business activity, and in the gravest cases dissolution.
- The 3x24 hour breach notification window means detection speed and evidence quality directly affect regulatory exposure.