SEO

Indonesia Personal Data Law for Foreign Brands

Three teams own one obligation and nobody holds all three. Where the exposure actually sits, and why WhatsApp breaks most assumptions.

Most foreign companies entering Indonesia treat data protection as a legal review item: send the privacy policy to counsel, get it localised, move on. That approach reliably produces a compliant document sitting on a website that does not match how the company actually handles data.

Law No. 27 of 2022 on Personal Data Protection reaches further than a policy page. It touches the consent flow that product owns, the processing terms that commercial negotiates with local partners, and the hosting decision that engineering makes. Three different teams, one obligation, and by default nobody holds all three.

This article sets out what the law governs, where the obligation actually surfaces for a foreign brand, how it interacts with electronic system registration, and where the honest limits of a general article sit. Arfadia is a digital agency, not a law firm. This is orientation so you can brief an adviser better.

What the law governs, and what it does not

Law No. 27 of 2022 governs how personal data is collected, stored, transferred and used, and it applies to processing connected to Indonesian data subjects. It covers lawful basis for processing, transparency toward the individual, and the rights that individual can exercise.

What it does not do is replace or absorb the separate obligation to register your electronic system. That is a common misreading, and it produces companies that are careful about data while operating an unregistered service, or properly registered while handling data on assumptions imported from another jurisdiction.

Two regimes, independent failure

Registration and Data Are Not the Same Obligation

Satisfying one does nothing for the other.

Layer one

Electronic system registration

Establishes that the regulator knows who you are and can reach you. Triggered by whether Indonesian users can access the service, not by incorporation.

Ministerial Regulation No. 5 of 2020, as amended by No. 10 of 2021. Enforced through access blocking.

Layer two

Personal data protection

Governs collection, storage, transfer and use of personal data once you are operating. Covers lawful basis, transparency and data subject rights.

Law No. 27 of 2022. Applies to processing connected to Indonesian data subjects.

Where the gap opens

A company can be properly registered while handling data on assumptions carried in from another market, or careful with data while operating a service that was never registered. Neither failure is visible from the other side.

The three places it actually surfaces

For a foreign brand, data obligations do not arrive as one item. They appear in three places at once, and each sits with a different function inside the company.

The consent mechanism on the service. This is product's territory. It covers what the user is told at the point of collection, what they are asked to agree to, how granular that agreement is, and whether declining is a real option. A consent flow designed for another jurisdiction's rules will not automatically satisfy a different framework, and it is the part users and regulators can both see.

The processing terms with local parties. This is commercial or legal territory. Any Indonesian distributor, reseller, agency, payment aggregator or logistics provider that touches customer data creates a processing relationship that needs to be defined. This is the part most often discovered late, usually when a partner asks for a customer list and somebody realises there is no agreement covering it.

Where the data physically sits. This is engineering territory. Localisation requirements apply to certain categories of data rather than uniformly, which means the answer depends on the sector and the nature of what is being processed. There is no single rule to look up, and this is one of the clearest cases for sector specific advice rather than a general article.

One obligation, three owners

Nobody Holds All Three by Default

Which is exactly how gaps open in companies that believe they have handled it.

Product

Consent mechanism

What the user is told at collection, what they agree to, how granular that agreement is, and whether declining is genuinely available.

Typical failure: a flow designed for another jurisdiction, shipped unchanged.

Commercial or Legal

Processing terms with partners

Every Indonesian distributor, reseller, agency, payment aggregator or logistics provider touching customer data creates a relationship that has to be defined.

Typical failure: discovered when a partner requests a customer list.

Engineering

Where data physically resides

Localisation requirements apply to certain categories rather than universally. Sector and data type determine the position.

Typical failure: an architecture decision made before anyone asked the question.

Why marketing has more exposure here than it expects

Data protection tends to be filed under legal risk. For a brand doing digital marketing in Indonesia, a large share of the actual processing sits inside marketing operations, and that is worth saying out loud because it is where the practical exposure concentrates.

Email lists, lead capture forms, WhatsApp Business conversations, advertising audience uploads, retargeting pixels, CRM records, influencer campaign data, marketplace customer messages. All of that is personal data processing, and most of it is configured by marketing teams and agencies rather than by legal.

There is a specific consequence for Indonesia that follows from this. First party data becomes considerably more valuable when the alternatives get harder, and Arfadia's own benchmark research points at the same conclusion from the demand side: 62 percent of Indonesian businesses still rely on last click attribution, which systematically under credits organic and content while over crediting paid search. Companies that build clean, consented first party data and measure properly end up with an advantage that is structural rather than tactical.

WhatsApp is the case that breaks most assumptions

There is one channel in Indonesia that sits outside almost every data governance framework a foreign company brings with it, and it happens to be the most used channel in the country.

Roughly nine in ten Indonesians use WhatsApp every month, according to DataReportal's Digital 2026 figures, with daily time close to TikTok's. For businesses it is not a messaging app in the Western sense. It is a primary sales, support and CRM channel, and conversations there routinely contain names, phone numbers, addresses, order details, payment confirmations and sometimes identity documents.

That creates three questions most companies have not asked. Who inside the organisation, or inside the agency, has access to those conversation histories. Where do exported chat records live once someone has downloaded them into a spreadsheet. And what happens to a customer's data when the staff member handling their account leaves.

None of that is exotic. It is the ordinary operating reality of selling in Indonesia, and it is invisible to a data governance policy written around web forms and CRM systems. A company can have a well drafted privacy notice and a properly configured consent banner while its highest volume customer channel runs on personal devices with no access controls at all.

This is also the clearest illustration of the wider point in this article. The obligation does not live where the policy lives. It lives where the data actually moves, and in Indonesia a large share of it moves through a channel that no media plan, no analytics dashboard and no standard compliance checklist accounts for.

The part that is easy to get wrong quietly

Three patterns recur, and none of them look like violations from the inside.

Importing a consent flow. A company with a carefully built European or Singaporean consent experience ships it unchanged to Indonesia on the reasoning that it is the stricter standard. Stricter in one framework does not mean compliant in another, because the requirements differ in kind rather than only in degree.

Treating an agency as invisible. An agency that runs your ads, manages your CRM, or handles your WhatsApp Business account is processing personal data. That relationship needs terms. Assuming a service agreement covers it is a common gap, and it is one both parties tend to discover at the same awkward moment.

Assuming the local partner has it handled. Appointing an Indonesian distributor or licensed importer solves several regulatory problems, which creates a comfortable impression that it solves this one too. It does not automatically, and the division of responsibility needs to be explicit rather than assumed.

The commercial argument, which is the one that gets acted on

Compliance framed purely as risk avoidance tends to be underfunded, because the return is the absence of an event nobody can point to. There is a better framing available here, and it is not spin.

Registration status and data handling practices are checkable, and Indonesian counterparties in regulated sectors check them. Financial services, healthcare and anything touching government procurement routinely verify compliance status before contracting, because their own obligations depend on it. Procurement teams have this on a checklist.

Which means a foreign brand's compliance posture affects deals before it affects penalties. And it means compliance that cannot be verified externally produces no commercial return at all, only the absence of a problem.

From cost to asset

Compliance Nobody Can Verify Returns Nothing

Four things that turn a legal position into something a buyer can check.

01

A privacy notice that matches reality

Written from how the company actually processes data, not adapted from another market's template. Readable by a buyer, not only by counsel.

02

Registration status stated publicly

Findable where procurement teams look, rather than only retrievable from a government portal by someone who already knows to check.

03

A named contact for data requests

A route for data subject requests that visibly exists and is answered. Its absence is one of the fastest credibility losses available.

04

Consistency across languages

If the Indonesian and English versions of a privacy notice say different things, the discrepancy is the finding.

WHY THIS MATTERS MORE EACH YEAR

AI assistants assemble answers from what is public

When someone asks whether a vendor is compliant, the answer is built from what is publicly discoverable and verifiable, not from what sits in a compliance folder. A position that cannot be found does not exist for that purpose.

What to do, and in what order

Map the processing before drafting anything. List every system and every partner that touches personal data connected to Indonesian individuals, including the marketing stack, because that is where most of it is and where it is least likely to be on anyone's list.

Assign the three ownership areas to named people. The consent flow, the partner terms and the hosting question each need someone accountable, and the gap between them is where problems live.

Get sector specific advice on localisation rather than looking for a general rule, because the requirement is category dependent and a general answer will be wrong for someone.

Then make the resulting position visible where buyers and AI assistants can verify it. That last step is the one that turns the spend into something with a commercial return, and it is routinely nobody's job.


Frequently Asked Questions


Does Indonesia's personal data law apply to a foreign company?

Law No. 27 of 2022 applies to processing connected to Indonesian data subjects. It operates alongside the separate obligation to register your electronic system under Ministerial Regulation No. 5 of 2020 as amended by No. 10 of 2021, which is triggered by whether Indonesian users can access your service rather than by incorporation. The two regimes fail independently, so satisfying one does not satisfy the other.


Do we have to store Indonesian customer data in Indonesia?

Not uniformly. Localisation requirements apply to certain categories of data rather than across the board, so the position depends on the sector and the nature of the processing. This is a question for a licensed adviser familiar with your sector rather than a general rule to look up.


Can we reuse our European or Singaporean consent flow?

Not on the assumption that a stricter framework automatically covers a different one. Requirements differ in kind rather than only in degree, so a flow built for another jurisdiction needs review against Indonesian requirements rather than being shipped unchanged.


Does our agency need a data processing agreement?

An agency running your advertising, managing your CRM or handling your WhatsApp Business account is processing personal data, and that relationship needs defined terms. Assuming a general service agreement covers it is a common gap, and both parties tend to discover it at the same point.


If we appoint an Indonesian distributor, is data their responsibility?

Not automatically. Appointing a local distributor or licensed importer resolves several regulatory requirements, which can create an impression that it resolves this one too. The division of responsibility for personal data needs to be explicit in the agreement rather than assumed.


Where does most of the exposure actually sit?

In marketing operations, more often than in legal. Email lists, lead capture forms, WhatsApp Business conversations, advertising audience uploads, retargeting pixels, CRM records and marketplace customer messages are all personal data processing, and most are configured by marketing teams and agencies rather than by counsel.


Does compliance have any commercial value, or only avoid penalties?

It has commercial value only if it is verifiable. Indonesian counterparties in regulated sectors routinely check compliance status before contracting because their own obligations depend on it, so a brand's posture affects deals before it affects penalties. Compliance that cannot be verified externally returns nothing beyond the absence of a problem.

Sources & References:

  • Law No. 27 of 2022 on Personal Data Protection, governing collection, storage, transfer and use of personal data, including lawful basis for processing, transparency obligations and data subject rights. Applies to processing connected to Indonesian data subjects.
  • Ministerial Regulation No. 5 of 2020 on Private Scope Electronic System Providers, as amended by Ministerial Regulation No. 10 of 2021. Registration is required of any party providing an electronic system to users in Indonesia, triggered by reachability rather than incorporation, and enforced primarily through access blocking. This regime operates alongside the personal data framework rather than as part of it.
  • Data localisation requirements apply to specified categories of data rather than universally, meaning sector and data type determine the position. Sector specific advice is required.
  • Registration status is publicly verifiable and is commonly checked by Indonesian counterparties in regulated sectors as part of procurement and contracting processes.
  • Attribution practice: 62 percent of Indonesian businesses rely on last click attribution, which systematically under credits organic search and content while over crediting paid search. Source: Arfadia primary client survey, n=127 Indonesian businesses, January to February 2026, published in Digital Marketing Benchmark Indonesia 2026, DOI 10.5281/zenodo.21100877.
  • WhatsApp usage in Indonesia: approximately nine in ten Indonesians use the platform monthly, with daily time close to TikTok. Source: DataReportal Digital 2026, Indonesia.
  • This article is orientation for commercial planning, not legal advice. Arfadia is a digital agency and does not provide data protection legal advice or file electronic system registrations, both of which require licensed consultants and lawyers. Current requirements should be verified with a qualified adviser before acting.
0 Comments 0 Comments
0 Comments 0 Comments