By Roffie Kurniawan ( September 2, 2026, 13:16 GMT | Insight) -- Indonesia has issued long-awaited implementing rules for its 2022 Personal Data Protection Law, spelling out company obligations on data breaches, overseas transfers, automated decision-making and high-risk processing ahead of their Jan. 16, 2027 entry into force. The regime allows fines of up to 2 percent of annual revenue, among other sanctions, but some elements — including cross-border transfer procedures and impact-assessment rules — still depend on a data protection authority that has yet to be established.Indonesia has issued the long-awaited implementing regulation for its Personal Data Protection Law, giving companies detailed rules on data breaches, overseas transfers, automated decision-making and high-risk processing, although key parts of the regime will depend on a data protection authority that has yet to be established....
Prepare for tomorrow’s regulatory change, today
MLex identifies risk to business wherever it emerges, with specialist reporters across the globe providing exclusive news and deep-dive analysis on the proposals, probes, enforcement actions and rulings that matter to your organization and clients, now and in the longer term.
Know what others in the room don’t, with features including:
- Daily newsletters for Antitrust, M&A, Trade, Data Privacy & Security, Technology, AI and more
- Custom alerts on specific filters including geographies, industries, topics and companies to suit your practice needs
- Predictive analysis from expert journalists across North America, the UK and Europe, Latin America and Asia-Pacific
- Curated case files bringing together news, analysis and source documents in a single timeline
Experience MLex today with a 14-day free trial.