Indonesia PDP Law Sanctions, Fines & Criminal Penalties: Financial Risk up to IDR 60 Billion

Under GDPR, fines reach 4% of global turnover. Under Indonesia’s PDP Law, administrative fines reach 2% of annual revenue + criminal penalties — boards are in scope.

Sanctions Ladder (Articles 57-73)

1. Administrative (by the PDP Authority):

  • Written warning → temporary suspension of processing → data deletion → fine up to 2% of annual revenue of the offending variable

2. Criminal (Articles 67-73):

  • Unlawfully obtaining / disclosing data: 5 years imprisonment / IDR 5 billion fine
  • Disclosing data: 4 years / IDR 4 billion
  • Falsifying data: 6 years / IDR 6 billion
  • Additional: criminal proceeds confiscated + compensation up to IDR 60 billion to subjects

Who Is Liable?

Corporations can be prosecuted — not just individual IT staff. If the violation stems from missing board-level policies, directors & the corporation are liable. Cyber insurance does not cover criminal fines.

Simple Calculator

Offending-variable turnover of IDR 1 trillion → maximum administrative fine of IDR 20 billion (2%) + civil compensation + litigation costs. Reputation damage not included.

Board question: “Do we have ROPA + DPIA + 72-hour evidence?” — if not, fines escalate.

PDP Sanctions Risk Audit — 10 Days → · Controller Obligations →