Login / Register ID | EN
This page has no official English version. It was translated automatically and may contain errors. Read the original in Indonesian →
Setahun UU PDP Berlaku Penuh: Pelajaran dari Insiden Data Pribadi yang Terus Berulang
Image by succo from Pixabay
IT Bisnis

One Year of Full Implementation of UU PDP: Lessons from Repeated Personal Data Incidents

October 17, 2024 marks a turning point in personal data governance in Indonesia. After two years of transition, Law Number 27 of 2022 on Personal Data Protection (UU PDP) officially comes into full effect. Every organization that processes personal data, from large corporations to public services, is now bound by obligations that were previously only recommendations.

More than a year in, the compliance landscape is still far from ideal. Data breach incidents make headlines almost every month. Many organizations label their privacy policies as “compliant with UU PDP,” while the content is nearly identical to pre-2024 documents. The only change is the stamp of approval.

The Reality of DPO Implementation on the Ground

UU PDP requires organizations that process personal data on a large scale to appoint a Data Protection Officer (DPO). It sounds simple on paper. In practice, it is not.

Many companies appoint the DPO as an additional role for legal or IT staff who are already overwhelmed. Without specific authority, without a separate budget, and without direct access to the board of directors, the result is that the DPO exists in the structure but lacks the power to drive substantive change. Compliance practitioners in the financial sector often complain about the same issue: incident reports do not reach the DPO until 72 hours have passed, whereas Article 46 of UU PDP requires notification to data subjects and authorities within that timeframe.

Recurring Incident Patterns

Data breach incidents in Indonesia from 2025 to 2026 show a similar pattern year after year. The entry vectors are generally not sophisticated zero-day exploits. The dominant method is phishing that successfully obtains internal account credentials or misconfigured cloud storage.

Once inside, attackers typically move laterally for weeks before large-scale exfiltration. This lateral movement period should be detectable by adequate log monitoring. However, security teams in most organizations still lack analysts with the experience to operate SIEM effectively. Investing in tools without investing in people is a common recipe for failure.

Commonly Overlooked Audit Gaps

Three compliance gaps consistently appear in initial audits. The first is the Records of Processing Activity (RoPA), which is created once and then left to gather dust in a filing cabinet. RoPA should be a living document that reflects every change in data flow, including the addition of new vendors or product features involving personal data.

Next, there are vague retention policies. Many organizations retain customer data far longer than operational needs require, without clear legal justification. Every byte stored without purpose is a liability waiting to be activated when an incident occurs.

Lastly, and often most severely, is weak vendor management. Data often leaks not from internal systems, but from third parties that receive access without adequate Data Processing Agreements. Cloud providers, marketing services, analytics vendors, all can become points of failure.

What to Expect Going Forward

The establishment of the Personal Data Protection Agency mandated by the law is a long-awaited oversight point for many. Until this agency operates effectively, enforcement continues through Komdigi and sectoral ministries. Inconsistencies in standards across sectors remain a routine complaint among practitioners.

What is more crucial is not the presence of the agency, but a shift in perspective. As long as personal data is viewed as an asset that can be harvested freely without ethical considerations, no matter how strong the regulations are, they will lag behind data-hungry innovations. The lesson learned over the past year is clear: formal compliance alone is not enough. What is needed is a sincere willingness to answer the most fundamental question, “What data do we truly need to process, and for what purpose?”

References:

  • Government of the Republic of Indonesia – Law Number 27 of 2022 on Personal Data Protection → jdih.setneg.go.id
  • Ministry of Communication and Digital – Socialization of UU PDP Implementation → komdigi.go.id
  • ELSAM – Critical Notes on the Implementation of UU PDP → elsam.or.id
  • BSSN – Cybersecurity Landscape in Indonesia → bssn.go.id