Indonesia PDP Law Sanctions, Fines & Criminal Penalties: Financial Risk up to IDR 60 Billion
Under GDPR, fines reach 4% of global turnover. Under Indonesia’s PDP Law, administrative fines reach 2% of annual revenue + criminal penalties — boards are in scope.
Sanctions Ladder (Articles 57-73)
1. Administrative (by the PDP Authority):
- Written warning → temporary suspension of processing → data deletion → fine up to 2% of annual revenue of the offending variable
2. Criminal (Articles 67-73):
- Unlawfully obtaining / disclosing data: 5 years imprisonment / IDR 5 billion fine
- Disclosing data: 4 years / IDR 4 billion
- Falsifying data: 6 years / IDR 6 billion
- Additional: criminal proceeds confiscated + compensation up to IDR 60 billion to subjects
Who Is Liable?
Corporations can be prosecuted — not just individual IT staff. If the violation stems from missing board-level policies, directors & the corporation are liable. Cyber insurance does not cover criminal fines.
Simple Calculator
Offending-variable turnover of IDR 1 trillion → maximum administrative fine of IDR 20 billion (2%) + civil compensation + litigation costs. Reputation damage not included.
Board question: “Do we have ROPA + DPIA + 72-hour evidence?” — if not, fines escalate.
PDP Sanctions Risk Audit — 10 Days → · Controller Obligations →