{"id":147468,"date":"2026-08-12T13:58:55","date_gmt":"2026-08-12T13:58:55","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=147468"},"modified":"2026-08-12T14:01:21","modified_gmt":"2026-08-12T14:01:21","slug":"indonesia-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/indonesia-tmt\/","title":{"rendered":"Indonesia: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-147468","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-indonesia"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">SSEK Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2019\/03\/SSEK-logo.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">SSEK Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2019\/03\/SSEK-logo.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Indonesia<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Indonesia, proprietary rights in software are protected through a combination of copyright, patent, and trade secret law.<\/p>\n<p>Computer programs are expressly protected as literary works under Law No. 28 of 2014 regarding Copyright, dated October 16, 2014, as last amended by Law No. 1 of 2026 regarding Criminal Adjustment, dated January 2, 2026 (\u2018Copyright Law\u2019). Copyright protection arises automatically under the declarative principle set out in the Copyright Law, meaning protection subsists from the moment a work is fixed in tangible form, without the need for registration. While recordation of a copyrighted work with the Directorate General of Intellectual Property (\u2018DGIP\u2019) is not mandatory, it is strongly recommended, as a certificate of recordation constitutes prima facie evidence of ownership in any subsequent enforcement action.<\/p>\n<p>Patent protection under Law No. 13 of 2016 regarding Patents, dated August 26, 2016, as last amended by Law No. 65 of 2024 regarding the Third Amendment to Law No. 13 of 2016, dated October 28, 2024 (\u2018Patent Law\u2019), is available in principle for software-related inventions. Under Article 4(d) of the Patent Law, a computer program as such is excluded from patentable subject matter, except where the invention qualifies as a computer-implemented invention. The official elucidation to Article 4(d) of the Patent Law clarifies that a computer program consisting solely of program instructions, without technical character, technical effect, or the solving of a technical problem, remains excluded from patentability. By contrast, a computer-implemented invention that solves a problem having a technical character and effect may be treated as a patentable Invention. The elucidation gives as examples GPS-based vehicle navigation software, automatic distance-keeping cruise control software, and Internet of Things (\u2018IoT\u2019)-based remote control of household appliances via the internet. A similar technical-character\/technical-effect qualification applies under Article 4(g) of the Patent Law to the separate statutory exclusion of theories and methods in the fields of science and mathematics.<\/p>\n<p>Source code, algorithms, and other confidential technical materials associated with software may also be protected as trade secrets under Law No. 30 of 2000 regarding Trade Secrets, dated December 20, 2000, as last amended by Law No. 1 of 2026 regarding Criminal Adjustment, dated January 2, 2026 (\u2018Trade Secrets Law\u2019), provided the information has economic value and is not known to the public. Trade secrets do not require registration, although trade secret licenses should be recorded with the DGIP.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Absent a contractual agreement to the contrary, Article 36 of the Copyright Law provides that the author and copyright holder of a work created in an employment relationship or under commission is the party who created the work, namely, the developer or consultant, rather than the commissioning customer. This differs from the position in many common law jurisdictions, where work-for-hire arrangements typically vest ownership in the commissioning party by default.<\/p>\n<p>A separate default rule applies where the work is created by an employee within an employment relationship in the public sector. Under Article 35 of the Copyright Law, unless otherwise agreed, the relevant government institution is deemed to be the author of a work created by an employee in the course of official duties, with royalties payable to the employee if the work is used commercially. This provision, however, applies specifically to works made in a civil service employment relationship and does not extend to commissioned development in the private sector.<br \/>\nA related but distinct rule applies under Article 34 of the Copyright Law where a work is designed by one party but executed by another under the designer\u2019s direction and supervision. In such circumstances, the designer, rather than the executor, is deemed to be the author.<\/p>\n<p>Given this default, customers commissioning software development in Indonesia should ensure that the development agreement contains an express assignment or license of intellectual property rights, as reliance on the statutory default is likely to leave beneficial rights with the developer rather than the customer.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a standalone software liability statute. Liability for harm caused by software or computer systems is addressed through a combination of the general fault-based liability regime under the Indonesian Civil Code (\u2018ICC\u2019), sector-specific electronic systems regulation, and an operator-liability default applicable to automated or \u2018Electronic Agent\u2019 functionality.<\/p>\n<p>Under the ICC, a valid contract requires the parties\u2019 consent, legal capacity, a particular object and lawful cause, and a party in default is obligated to provide compensation for losses arising from a failure to perform contractual obligations. Separately, liability for wrongful acts is assessed on a fault basis, requiring an unlawful act, fault or negligence, damage, and a causal link between the act and the damage.<\/p>\n<p>Where the software operates as an \u2018Electronic Agent,\u2019 being a component of an electronic system designed to automatically perform actions based on input, without real-time human control, Article 21(2) of Law No. 11 of 2008 regarding Electronic Information and Transactions, dated April 21, 2008, as last amended by Law No. 1 of 2026 regarding Criminal Adjustment, dated January 2, 2026 (\u2018EIT Law\u2019), places liability for electronic transactions conducted by the Electronic Agent on its operator by default, shifting to the user only where losses arise from user negligence. Government Regulation No. 71 of 2019 regarding the Implementation of Electronic Systems and Transactions, dated October 10, 2019 (\u2018GR 71\/2019\u2019), further requires electronic system providers to ensure their systems are reliable, secure and operate as intended, and imposes administrative liability for failures that cause disruption or loss.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The use and misuse of software and computer systems is principally governed by the cybercrime provisions of the EIT Law, which criminalise a broad range of conduct involving unauthorised access, interference and misuse of electronic systems.<\/p>\n<p>Article 30 of the EIT Law prohibits intentional and unauthorised access to another person\u2019s computer or electronic system, including by violating or bypassing its security system. Article 33 of the EIT Law makes it unlawful to intentionally and without right cause an electronic system to fail to function as intended, capturing conduct such as denial-of-service attacks. Article 34 of the EIT Law separately prohibits the creation, distribution, sale, or possession of hardware or software specifically developed to facilitate unauthorised access or system interference, such as malware, keyloggers, or exploit kits.<\/p>\n<p>Article 31 of the EIT Law prohibits the interception of electronic information or documents without legal authority, subject to an exemption for lawful interception conducted for law enforcement purposes at the request of the police, prosecutor\u2019s office or other authorised institution.<\/p>\n<p>Beyond the EIT Law, Article 17 of the Trade Secrets Law penalises the unlawful disclosure or misuse of confidential business information, and Article 113(3) of the Copyright Law imposes sanctions for unauthorised reproduction or distribution of software.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>A software vendor providing software, including software-as-a-service or cloud-based solutions, to customers in Indonesia is generally required to register as an Electronic System Provider (\u2018ESP\u2019) with the Ministry of Communication and Digital Affairs (\u2018MOCDA\u2019), pursuant to Minister of Communication and Informatics Regulation No. 5 of 2020 regarding Private Electronic System Providers, dated November 24, 2020, as amended by Minister of Communication and Informatics Regulation No. 10 of 2021 regarding the Amendment of MOCI Reg. 5 of 2020, dated May 21, 2021 (\u2018MOCI Reg. 5\/2020\u2019). ESP registration is intended to demonstrate the general operability of the electronic system, compliance with applicable data protection requirements, and satisfaction of minimum quality and security standards.<\/p>\n<p>GR 71\/2019 sets out substantive requirements for the hardware and software used by an ESP, including requirements relating to system security, interconnectivity, and compatibility, as well as obligations for vendors to provide technical support and maintenance and ensure service continuity. Under GR 71\/2019, ESPs classified as \u2018public scope\u2019 are required to process and store data within Indonesia, subject to a limited exception where the relevant technology is unavailable domestically. ESPs classified as \u2018private scope,\u2019 which is the classification typically applicable to commercial SaaS and cloud vendors, may store and process data either inside or outside of Indonesia, provided the vendor is able to grant access to the electronic system and data for supervisory and law enforcement purposes.<\/p>\n<p>Cloud computing is further addressed under MOCI Reg. 5\/2020, which defines cloud computing as a model for providing on-demand network access to a shared set of configurable computing resources. Cloud vendors serving certain regulated sectors, such as banking or insurance, may also be subject to sector-specific outsourcing and IT risk management obligations, discussed further in the IT Outsourcing section below.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesian law does not prohibit contractual limitation of liability clauses, and Indonesian courts will generally give effect to a negotiated liability cap as an expression of freedom of contract, subject to the general ICC principle that liability for wrongful acts committed with intent or gross negligence, and certain categories of loss, may not be capable of exclusion as a matter of public policy or good faith.<\/p>\n<p>Subject to this qualification, it is common commercial practice for software vendors operating in the Indonesian market, particularly multinational vendors and larger domestic providers, to include a liability cap in their standard terms or negotiated agreements. However, there is no single, well-established market-standard quantum for such caps under Indonesian law or practice. The level of the cap in practice tends to follow the norms of the vendor\u2019s home jurisdiction or industry sector (for example, a multiple of annual fees paid, or a fixed sum), rather than any distinctly Indonesian market convention.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As a matter of Indonesian law, there is no statutory requirement that any of the categories listed above be carved out of a negotiated liability cap, as this is a matter for commercial negotiation between the parties.<\/p>\n<p>In particular, in the event of data protection or data security breaches, Indonesian data protection law itself imposes independent statutory liability on a data controller that exists regardless of any contractual cap agreed between the vendor and the customer. Such a contractual cap operates only between the contracting parties and does not limit the exposure of either party to the data protection regulator or affected data subjects under Law No. 27 of 2022 regarding Personal Data Protection, dated October 17, 2022, as amended by Law No. 1 of 2026 regarding Criminal Adjustment, dated January 2, 2026 (\u2018PDP Law\u2019).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesian law does not specifically regulate source code escrow arrangements, and no dedicated statutory framework governs the establishment or release conditions of a source code escrow in Indonesia. This is typically a matter for commercial negotiation between the parties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a general law specifically governing IT outsourcing transactions. The regulation of IT outsourcing is instead sector-specific, with the most developed framework applicable to regulated financial institutions.<\/p>\n<p>Commercial banks engaging third-party IT providers, including cloud service providers, are subject to Financial Services Authority (\u2018OJK\u2019) Regulation No. 11\/POJK.03\/2022 regarding the Implementation of Information Technology by Commercial Banks, dated October 7, 2022 (\u2018OJK Reg. 11\/2022\u2019). This regulation requires banks to maintain effective oversight of outsourced IT services, conduct due diligence on prospective providers, and enter into written agreements meeting minimum regulatory standards. A bank engaging a foreign IT provider for transaction processing must obtain prior OJK approval, and banks are generally required to maintain a data centre and\/or disaster recovery centre within Indonesia unless an exemption is granted. Analogous obligations apply to non-bank financial institutions, insurers, and investment managers under their respective sector regulators.<\/p>\n<p>Outside the regulated financial sector, an IT outsourcing arrangement is governed by general principles of Indonesian contract law under the ICC, together with the ESP registration and electronic systems requirements under GR 71\/2019 and MOCI Reg. 5\/2020, to the extent that the outsourced service involves the operation of an electronic system.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesian labour law does not provide for the automatic transfer of employment relationships when a service is outsourced to a third-party provider. Responsibility for labour protection, wages, welfare, working conditions, and the resolution of disputes involving outsourced workers remains with the outsourcing company that formally employs them.<\/p>\n<p>Accordingly, there is no automatic transfer of the employment relationship to the user company simply by virtue of a service transfer, including where there has been a breach of the underlying outsourcing agreement.<\/p>\n<p>The governing framework is Law No. 13 of 2003 regarding Manpower, dated March 25, 2003, as last amended by Law No. 1 of 2026 regarding Criminal Adjustment, dated January 2, 2026 (\u2018Employment Law\u2019), together with Government Regulation No. 35 of 2021 regarding Fixed-Term Employment Agreements, Outsourcing, Working and Resting Hours, and Termination of Employment, dated February 2, 2021 (\u2018GR 35\/2021\u2019). Most recently, Minister of Manpower Regulation No. 7 of 2026 regarding Outsourcing, issued April 30, 2026 (\u2018MOM Reg. 7\/2026\u2019), replaced the previous outsourcing framework and restricts the scope of permissible outsourcing to defined categories of supporting activity, including cleaning services, catering, security, drivers and transport, and operational support services (a category understood to extend to functions such as basic IT help desk support). The user company remains responsible for ensuring that the outsourcing company meets its obligations to outsourced workers, while the outsourcing company itself must register the outsourcing agreement with the local manpower office.<\/p>\n<p>The general purpose of this framework is to preserve the employment protections, statutory benefits, and dispute resolution rights of outsourced workers by fixing responsibility for those matters clearly with the outsourcing company as the employer, while imposing a compliance backstop on the user company, rather than guaranteeing outsourced staff continuity of role or employer.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal law governing telecommunications in Indonesia is Law No. 36 of 1999 regarding Telecommunications, dated September 8, 2000, as last amended by Law No. 1 of 2026 regarding Criminal Adjustment, dated January 2, 2026 (\u2018Telecommunications Law\u2019). The Telecommunications Law defines telecommunications as the transmission, delivery and\/or receipt of information via wire, optical, radio, or other electromagnetic systems, and distinguishes between telecommunications networks (fixed and mobile network infrastructure), telecommunications services (basic telephony, data communication, internet access and other multimedia services), and special telecommunications services (used for defined purposes such as broadcasting, navigation, aviation and emergency communications).<\/p>\n<p>The Telecommunications Law is implemented through Government Regulation No. 52 of 2000 regarding the Operation of Telecommunications, dated September 8, 2000 (\u2018GR 52\/2000\u2019), and Government Regulation No. 46 of 2021 regarding Post, Telecommunications, and Broadcasting, dated February 2, 2021 (\u2018GR 46\/2021\u2019), together with a series of MOCDA regulations. These include Minister of Communication and Informatics Regulation No. 5 of 2021 regarding Telecommunications Services, dated April 1, 2021, as amended by MOCDA Regulation No. 7 of 2026 regarding the Registration of Telecommunications Service Customers via Cellular Networks, dated January 19, 2026 (\u2018MOCI Reg. 5\/2021\u2019), governing the operation of telecommunications networks and services.<\/p>\n<p>More recently, MOCDA Regulation No. 14 of 2025 regarding Special Telecommunications for Personal Use, dated June 4, 2025 (\u2018MOCDA Reg. 14\/2025\u2019), and MOCDA Regulation No. 7 of 2025 regarding the Utilisation of Embedded Subscriber Identity Module Technology in Telecommunications Services, dated April 11, 2025 (\u2018MOCDA Reg. 7\/2025\u2019), have extended the regulatory framework to newer connectivity models, including embedded SIM (\u2018eSIM\u2019) technology supporting machine-to-machine and Io T connectivity.<\/p>\n<p>The general purpose of this legislative framework is to establish a licensed operating regime for the provision of telecommunications infrastructure and services in Indonesia, ensure network interoperability and service quality through mandatory interconnection and service level obligations, and preserve national oversight over spectrum allocation and critical communications infrastructure.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The operation of telecommunications networks, services or special telecommunications services in Indonesia may only be conducted by a licensed Indonesian legal entity, and a company must obtain the relevant network, service or special telecommunications license, as applicable, before offering services or deploying products in Indonesia.<\/p>\n<p>Where a business activity involves the use of the radio frequency spectrum, an operator must additionally obtain the relevant license under Minister of Communication and Informatics Regulation No. 7 of 2021 regarding the Use of the Radio Frequency Spectrum, dated April 1, 2021 (\u2018MOCI Reg. 7\/2021\u2019). Depending on the nature of the use, this may take the form of a radio frequency band license (Izin Pita Frekuensi Radio, or \u2018IPFR\u2019), a radio station licence (Izin Stasiun Radio, or \u2018ISR\u2019), or, for certified equipment, a class license. Spectrum-sharing arrangements between licensed operators are permitted, subject to contractual agreement between the relevant parties.<\/p>\n<p>Telecommunications equipment and devices manufactured, assembled or imported for use or distribution in Indonesia must separately undergo testing and certification to demonstrate compliance with applicable technical standards under Minister of Communication and Informatics Regulation No. 3 of 2024 regarding the Certification of Telecommunications Equipment and\/or Telecommunications Devices, dated May 23, 2024 (\u2018MOCDA Reg. 3\/2024\u2019). The certification obligation extends to a broad range of connected hardware, including radio frequency-enabled devices, and is administered through the relevant regulator\u2019s certification body, with importers, manufacturers, distributors, and brand owners or licensees required to demonstrate compliance with the applicable technical standard for each device type.<\/p>\n<p>For cellular mobile devices, the applicable technical standards are currently set out in MOCDA Decree No. 569 of 2025 regarding Technical Standards for Telecommunications Equipment and\/or Cellular Mobile Telecommunications Devices based on Long-term Evolution Technology Standards and International Mobile Telecommunications-2020 Technology Standards, dated January 19, 2026 (\u2018MOCDA Decree 569\/2025\u2019). Among other requirements, the decree establishes minimum domestic component (Tingkat Komponen Dalam Negeri, or \u2018TKDN\u2019) thresholds of 35% for subscriber stations and IMT-2020 devices and 40% for base stations.<\/p>\n<p>Separately, telecommunications operators are subject to ongoing financial obligations tied to their licence, including the Telecommunications Service Fee (Biaya Hak Penyelenggaraan, or \u2018BHP\u2019) and Universal Service Obligation (\u2018USO\u2019) contribution, generally calculated at 0.5% and 1.25%, respectively, of gross revenue derived from telecommunications operations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a dedicated, standalone law governing lawful interception or law enforcement access to communications data. The framework instead derives from parallel provisions in the EIT Law and the Telecommunications Law. Article 31 of the EIT Law prohibits the interception of electronic information or documents generally, but this prohibition does not apply where interception is conducted for law enforcement purposes at the request of the police, prosecutor\u2019s office, or another authorised institution. Article 42 of the Telecommunications Law similarly permits a telecommunications service provider, for criminal justice purposes, to record and provide information upon either a written request from the Attorney General or the Chief of Police in relation to certain offences, or a lawful request from investigators in relation to specific offences.<br \/>\nInvestigators are separately granted broad powers under Article 43 of the EIT Law to conduct searches, confiscate evidence, request information from electronic system operators, inspect and seize IT equipment used in connection with an offence, and order the temporary suspension of access to social media accounts, bank accounts, electronic money, and digital assets.<\/p>\n<p>The applicable framework does not, on its face, require judicial pre-authorisation of an interception request in the manner of a warrant. Instead, the mechanism involves an executive request from a named authorised agency, subject to requirements that the request be in writing and directed at specified categories of offences. There is no confirmed statutory requirement that the subject of a request be notified, before or after the fact.<\/p>\n<p>The potential for judicial challenge is illustrated in Frederick Rachmat v PT XL Axiata Tbk, Decision No. 79\/Pdt.G\/2023\/PN Jkt.Sel (South Jakarta District Court, December 11, 2023). In that case, a telecommunications subscriber brought a civil claim alleging unlawful interception arising from a disputed call-forwarding feature. The court held the claim inadmissible as premature, finding that the occurrence of unlawful interception under Article 31 of the EIT Law and Article 40 of the Telecommunications Law must first be established through criminal proceedings before a civil claim grounded on the same allegation may proceed.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesian telecommunications regulation does not provide a standalone set of technical cybersecurity standards specific to telecommunications infrastructure. Instead, telecommunications operators are subject to security obligations derived from their licensing and operational conditions, together with the general electronic systems and cybersecurity framework applicable to all electronic system providers.<\/p>\n<p>Presidential Regulation No. 82 of 2022 regarding the Protection of Vital Information Infrastructure, dated May 24, 2022 (\u2018PR 82\/2022\u2019), designates information and communication technology, which includes telecommunications infrastructure, as one of the essential sectors whose electronic systems may be designated Vital Information Infrastructure.<\/p>\n<p>Operators of Vital Information Infrastructure, whether government or private entities, are required to implement applicable security standards, manage and report risks, establish an incident response team with prompt reporting obligations, and undergo annual security maturity assessments. These requirements are reinforced by Presidential Regulation No. 47 of 2023 regarding National Cyber Security Strategy and Cyber Crisis Management, dated July 20, 2023 (\u2018PR 47\/2023\u2019), which designates the National Cyber and Crypto Agency (Badan Siber dan Sandi Negara, or \u2018BSSN\u2019) as the central coordinator for national cybersecurity. The framework is further implemented through BSSN Regulation No. 1 of 2024 regarding Cyber Incident Management, dated January 18, 2024 (\u2018BSSN Reg. 1\/2024\u2019), and BSSN Regulation No. 2 of 2024 regarding Cyber Crisis Management, dated January 18, 2024 (\u2018BSSN Reg. 2\/2024\u2019). These regulations require electronic system providers, including telecommunications operators, to establish a Cyber Incident Response Team and report high-risk incidents within 24 hours, or within 1&#215;24 hours for incidents involving Vital Information Infrastructure.<\/p>\n<p>As a pending legislative development, the draft Law regarding Cyber Security and Resilience, currently before the House of Representatives, would formalise this framework at the statutory level. The draft law would expressly designate telecommunications networks and infrastructure as protected \u2018Information Infrastructure\u2019 and introduce baseline obligations relating to governance, protection, detection, incident response, and recovery for operators of such infrastructure. It would also establish risk-tiered certification requirements for digital-element products and services and introduce a materially enhanced criminal sanctions regime, including imprisonment of up to 15 years for attacks on infrastructure designated as Critical Information Infrastructure.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a dedicated domestic standard-setting body responsible for developing technical standards for mobile communications or connected technologies. The National Standardisation Agency (Badan Standardisasi Nasional, or \u2018BSN\u2019) is responsible for adopting international standards, including relevant ISO\/IEC standards relating to IoT reference architecture, interoperability, sensor networks, and testing frameworks, into the Indonesian National Standard (Standar Nasional Indonesia, or \u2018SNI\u2019) framework. These adopted standards provide technical guidance but do not, in themselves, constitute sector-specific regulation.<\/p>\n<p>Actual technical standard-setting for mobile telecommunications equipment is addressed indirectly through the equipment certification regime under MOCDA Reg. 3\/2024 and related decrees, including MOCDA Decree 569\/2025. This decree references the international mobile telecommunications technology standards as compliance benchmarks for equipment certification purposes, without naming or establishing an independent domestic standard-setting body. The specific domestic mechanism by which such international standards are formally adopted and conformity-assessed within Indonesia is set out in BSN Regulation No. 6 of 2021 regarding the Conformity Assessment Scheme for Indonesian National Standards for the Electrotechnical, Telecommunications, and Optical Products Sector, dated April 30, 2021, as last amended by BSN Regulation No. 5 of 2022 regarding the Second Amendment to BSN Regulation No. 6 of 2021, dated June 9, 2022 (\u2018BSN Reg. 6\/2021\u2019). This regulation confirms BSN\u2019s role as the domestic adoption and conformity-assessment body for this sector, rather than as an originating standard-setter.<\/p>\n<p>No dedicated standard-setting body or sector-specific standards framework has been identified in respect of digital health or connected and autonomous vehicle technologies in Indonesia.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As Indonesia does not operate an independent domestic standard-setting regime for connected devices, interoperability in practice is shaped by Indonesia\u2019s adoption of international ISO\/IEC standards into the SNI framework and by the mandatory equipment certification regime under MOCDA Reg. 3\/2024, rather than by locally originated interoperability standards.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal law governing data protection in Indonesia is the PDP Law. The PDP Law establishes a general framework for the protection of personal data across both electronic and non-electronic processing, setting out the lawful bases for data processing, the rights of data subjects, the obligations of personal data controllers and processors, breach notification requirements, and administrative and criminal sanctions for non-compliance.<\/p>\n<p>The PDP Law is supplemented by a series of implementing and adjacent regulations, including the EIT Law and GR 71\/2019, which address the processing of personal data within electronic systems; Minister of Communication and Informatics Regulation No. 20 of 2016 regarding the Protection of Personal Data in Electronic Systems, dated December 1, 2016 (\u2018MOCI Reg. 20\/2016\u2019); MOCI Reg. 5\/2020, which governs private ESPs; and MOCDA Regulation No. 5 of 2025 regarding Public ESPs, dated March 25, 2025 (\u2018MOCDA Reg. 5\/2025\u2019). Government Regulation No. 17 of 2025 regarding the Governance of Electronic System Operations in the Protection of Children, dated March 27, 2025 (\u2018GR 17\/2025\u2019), together with its implementing regulation, MOCDA Regulation No. 9 of 2026 regarding the Implementation of GR 17\/2025, dated March 6, 2026 (\u2018MOCDA Reg. 9\/2026\u2019), impose enhanced obligations specific to the personal data and online safety of child users.<\/p>\n<p>As a pending development, the Indonesian government is finalising a draft Government Regulation on the implementation of the PDP Law, which will be the first substantive implementing regulation issued under the PDP Law and is expected to provide detailed provisions on the obligations of personal data controllers, the role of data protection officers, and further clarification on consent requirements. The Personal Data Protection Institution mandated by the PDP Law to serve as the dedicated supervisory authority has not yet been established. In the interim, oversight functions are being performed by MOCDA.<\/p>\n<p>The general purpose of this framework is to implement the constitutional right to protection of personal data, bring Indonesia\u2019s data protection regime into closer alignment with international standards such as the EU General Data Protection Regulation, and support the growth of the digital economy by providing legal certainty for the collection, processing, and cross-border transfer of personal data.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the PDP Law, administrative sanctions for non-compliance may include a written warning, the temporary suspension of personal data processing activities, the deletion or destruction of personal data, and an administrative fine of up to 2% of the offending party\u2019s annual income or revenue.<\/p>\n<p>Criminal sanctions under the PDP Law apply to specific categories of unlawful conduct, including the unlawful obtaining, disclosure, use, or falsification of personal data. These offences carry imprisonment of between four and six years, together with fines determined by reference to applicable statutory fine categories. Where an offence is committed by a corporation, the corporation may be subject to a criminal fine of up to ten times the maximum fine applicable to an individual, as well as additional sanctions that may include confiscation of profits, business suspension, prohibition of certain activities, and licence revocation.<\/p>\n<p>Separately, where a personal data breach occurs within an electronic system, the EIT Law provides for imprisonment of up to 12 years and fines up to IDR 5 billion, which may overlap with, or apply in addition to, the PDP Law sanctions, depending on how the underlying conduct is characterised.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technology contracts involving the processing of personal data on behalf of another party are, as a matter of Indonesian law, subject to statutory minimum content requirements rather than purely negotiated terms. Under Article 51 of the PDP Law, a personal data processor must process personal data only in accordance with the documented instructions of the controller. The controller remains responsible for processing carried out on its behalf, and the processor requires the controller\u2019s prior written consent before engaging a sub-processor. Liability may shift to the processor where it processes data outside the controller\u2019s instructions or stated purpose of processing.<\/p>\n<p>Where two or more parties act as joint controllers, Article 18 of the PDP Law requires a written agreement addressing the roles, responsibilities, and relationship between the controllers, a jointly determined processing purpose and method, and a jointly appointed point of contact.<\/p>\n<p>Cross-border data transfer provisions in a technology contract must reflect the sequential test set out under Article 56 of the PDP Law. A transfer is permitted where the recipient jurisdiction provides a level of personal data protection that is equal to or higher than that required under the PDP Law. If this requirement is not met, the transfer may proceed where adequate and binding safeguards are in place, and failing that, only with the data subject\u2019s consent. Where the electronic system underlying the contract is classified as public scope under GR 71\/2019, a data localisation requirement may also apply.<\/p>\n<p>As to whether Indonesian technology contracts typically reference external regimes such as the EU General Data Protection Regulation or the California Consumer Privacy Act, this is common in practice where the contracting parties include a multinational counterparty, given that the PDP Law itself is understood to have been substantially modelled on the GDPR and shares many of its core concepts, including the controller\/processor distinction, the data protection impact assessment requirement, and breach notification timelines. Reference to an external regime in a purely domestic Indonesian technology contract without an international element would, however, not be standard drafting practice.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The EIT Law is the primary legal framework for cybersecurity and cybercrime in Indonesia, criminalising unauthorised access, system interference, data theft, phishing, malware, and illegal interception, and imposing baseline obligations on ESPs to ensure the reliability and security of their electronic systems. GR 71\/2019 elaborates on these ESP obligations, requiring risk management, business continuity planning, and mechanisms for the prevention, detection, and mitigation of cyber incidents.<\/p>\n<p>BSSN Regulation No. 8 of 2020 regarding Security Systems in the Implementation of Electronic Systems, dated November 23, 2020 (\u2018BSSN Reg. 8\/2020\u2019), sets out the substantive technical cybersecurity standard applicable to ESPs. It requires ESPs to implement an Information Security Management System and imposes certification requirements calibrated to a risk-tiered classification of electronic systems as strategic, high-risk or low-risk. PR 82\/2022 and PR 47\/2023 establish the Vital Information Infrastructure and national cyber crisis management frameworks described above, with BSSN designated as the central coordinating authority. Sector regulators, in particular the Indonesian central bank, Bank Indonesia (\u2018BI\u2019), and the OJK impose further sector-specific cyber resilience requirements on regulated financial institutions.<\/p>\n<p>As a pending development, Indonesia is finalising a draft Law regarding Cyber Security and Resilience, which would for the first time establish a dedicated statutory cybersecurity framework, formalising obligations around governance, incident response, Critical Information Infrastructure designation, supply chain security, and a materially strengthened sanctions regime.<\/p>\n<p>The general purpose of this framework, distinct from the data protection regime, is to protect the confidentiality, integrity and availability of electronic systems and infrastructure as such, including where no personal data is involved, and to build institutional and sectoral resilience against cyber threats at a national level.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a single cybersecurity statute with its own self-contained sanctions ceiling. The applicable maximum sanction depends on which underlying law is triggered by the relevant conduct. Under the EIT Law, the most serious cybercrime offences, including unauthorised access or system interference causing material damage, carry penalties of up to 12 years\u2019 imprisonment and\/or a fine of up to IDR 5 billion. Where an incident also constitutes a personal data breach, the sanctions under the PDP Law described above, including an administrative fine of up to 2% of annual revenue and criminal penalties of up to six years\u2019 imprisonment, may apply in addition. BSSN\u2019s own administrative enforcement powers under BSSN Reg. 8\/2020 are presently limited to the issuance of a written reprimand.<\/p>\n<p>As a pending legislative development, the draft Law regarding Cyber Security and Resilience would introduce materially higher sanctions for attacks on Critical Information Infrastructure, including imprisonment of up to 15 years or a Category VIII fine. These penalties may be increased by a further one-third where the conduct threatens state sovereignty, the public interest, or public safety.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. All ESPs, whether public or private scope, are required to register with MOCDA under GR 71\/2019 and MOCI Reg. 5\/2020, and are separately required under BSSN Reg. 8\/2020 to conduct a self-assessment of their electronic system\u2019s risk classification (strategic, high-risk or low-risk) and report the results to BSSN. BSSN then verifies the assessment and determines the applicable certification requirements, which may include Indonesian National Standard ISO\/IEC 27001 certification or another BSSN-prescribed standard.<\/p>\n<p>Sector-specific registration and cybersecurity compliance obligations apply in the financial services sector, where banks and financial institutions must comply with cyber resilience and information security requirements under OJK Reg. 11\/2022 and BI Regulation No. 2 of 2024 regarding Information System Security and Cyber Resilience for Payment System Organisers, dated April 22, 2024 (\u2018BI Reg. 2\/2024\u2019). PR 82\/2022 further designates operators of essential sectors, including government administration, energy, transport, finance, health, information and communications technology, food and defence, as candidates for designation as Vital Information Infrastructure operators, triggering enhanced registration, risk management, and incident response team obligations under that regime.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Cybersecurity incident reporting in Indonesia operates on a tiered basis depending on the nature of the incident and the classification of the affected system. Under Article 24(3) of GR 71\/2019, an ESP is required to secure the relevant electronic information and documents and immediately report to law enforcement and the relevant ministries or institutions any system failure or disruption caused by external action that seriously affects the electronic system. In practice, such reports are directed to MOCDA and BSSN.<\/p>\n<p>Where the incident constitutes a failure of personal data protection under the PDP Law, the data controller is required to provide written notification to affected data subjects and the relevant supervisory institution (currently MOCDA, pending the establishment of the dedicated Personal Data Protection Institution) no later than 3&#215;24 hours from becoming aware of the incident. The notification must include the personal data affected, when and how the breach occurred, and the remedial steps taken. The controller must also notify the public where the breach disrupts public services or has a serious impact on the public interest.<\/p>\n<p>BSSN Reg. 1\/2024 imposes a further and more specific reporting obligation for incidents classified as at least high risk or impact. An ESP\u2019s Cyber Incident Response Team must report such an incident within 24 hours of discovery to the relevant sectoral Cyber Incident Response Team, with a copy to the National Cyber Incident Response Team. Where no sectoral team exists, the incident must be reported directly to the relevant supervising ministry or agency. For systems designated as Vital Information Infrastructure, the reporting timeline is shortened to 1&#215;24 hours. At a minimum, the report must include the reporting party\u2019s contact details, a description and chronology of the incident, and its impact.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not currently have a dedicated AI regulator or binding AI-specific legislation. Regulatory oversight of AI is instead distributed across several bodies according to sector and function. MOCDA is the principal ministry responsible for general AI policy and ethics guidance, having issued Minister of Communication and Informatics Circular Letter No. 9 of 2023 regarding the Ethics of Artificial Intelligence, dated December 19, 2023 (\u2018MOCI CL 9\/2023\u2019). MOCDA is understood to be coordinating the drafting of a forthcoming Draft Presidential Regulation on AI. The OJK exercises AI-related oversight within the financial services sector through its broader IT governance and cyber-resilience regulations and has issued a non-binding Code of Ethics Guideline on Responsible and Trustworthy AI in the financial technology industry. Separately, the Indonesian Press Council regulates the use of AI in journalism under Press Council Regulation No. 1\/PERATURAN-DP\/I\/2025 of 2025, dated January 22, 2025 (\u2018PCR Reg. 1\/2025\u2019). Where AI processing involves personal data, the general enforcement framework under the PDP Law applies, with MOCDA currently exercising the relevant supervisory functions on an interim basis. Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia has not enacted binding AI-specific legislation. AI is instead regulated indirectly under the EIT Law, which categorises AI systems within the broader concept of an \u2018Electronic Agent,\u2019 defined as a component of an electronic system designed to automatically perform actions on electronic information without direct real-time human control. Under Article 21(2) of the EIT Law, liability for actions taken by an Electronic Agent rests by default with its operator rather than the end user, subject to a carve-out where losses arise from user negligence. GR 71\/2019 further sets out general principles applicable to Electronic Agent providers, including prudential and consumer protection principles and requirements around the security and integration of the underlying information technology systems.<\/p>\n<p>The principal non-binding instrument is MOCI CL 9\/2023, which sets out nine ethical principles applicable to AI business actors and ESPs: inclusivity, humanity, security, accessibility, transparency, credibility and accountability, personal data protection, sustainable development, and intellectual property. As a circular letter, non-compliance does not itself attract direct sanctions, although conduct breaching these principles may independently constitute a breach of another applicable law, such as the PDP Law.<\/p>\n<p>As a pending legislative development, a Draft Presidential Regulation on AI is understood to be targeted for submission to the President, and would introduce a structured, risk-based compliance regime, including transparency obligations regarding data sources and technical risk, mandatory human oversight for AI decisions with a significant impact on human rights, life or welfare, and a four-component monitoring and reporting framework. The Vice Minister of MOCDA has indicated that the draft is not expected to introduce new sanctions specific to AI, with enforcement to continue under existing regulatory frameworks. Sector-specific AI provisions also exist under Minister of Trade Regulation No. 19 of 2026 regarding the Implementation of Trading Through Electronic Systems, dated June 8, 2026 (\u2018MOT Reg. 19\/2026\u2019), which requires e-commerce business actors using AI to label AI-generated content, ensure accuracy of AI-generated information, and, for electronic trading organisers, implement proportionate AI governance and a complaint-handling mechanism.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no legal provisions in Indonesia specific to Large Language Models, generative AI or agentic AI as a distinct category. Such systems are regulated, to the extent they are regulated at all, under the general Electronic Agent framework of the EIT Law and GR 71\/2019 described above, applicable to AI systems generally rather than to generative or agentic systems specifically.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesian law does not currently mandate specific AI risk provisions in technology contracts by statute. However, given the EIT Law\u2019s operator-liability default under Article 21(2), whereby liability for an Electronic Agent\u2019s actions rests with the operator rather than the end user or customer absent user negligence, it is considered strongly advisable, and increasingly standard commercial practice, for AI service agreements in Indonesia to expressly allocate liability between the AI provider and its customer for inaccurate, harmful, biased, or discriminatory AI outputs, including through indemnity and limitation of liability provisions, rather than leaving the statutory default to apply by omission.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the current Copyright Law, copyright subsists only in original works resulting from human intellectual effort. Where a human directs, selects or curates AI-generated output, that person may be deemed the author, but the current Copyright Law does not expressly address works created autonomously by AI, and AI-generated content lacking meaningful human involvement is unlikely to qualify for copyright protection. The current Copyright Law also contains no express text and data mining exception, creating a further layer of uncertainty for the training of AI models on copyrighted Indonesian-sourced content absent a license or reliance on the narrower education and research exceptions.<\/p>\n<p>This position is expected to be substantially clarified by the pending revision of the Copyright Law, which is before the House of Representatives and included in the 2026 National Legislative Program. The draft bill introduces, for the first time, express statutory criteria for the protection of AI-assisted works, providing that a work generated with the assistance of artificial intelligence is protected as a copyrighted work if it satisfies, at minimum: (a) a creative conception originating from a human; (b) a process of human selection, curation, and refinement of the output; (c) a documented and traceable creation process; (d) compliance with applicable artificial intelligence ethical standards; and (e) a final result reflecting human aesthetic choice. A work generated by artificial intelligence without meaningful human intellectual involvement is expressly excluded from copyright protection.<\/p>\n<p>The draft bill further imposes disclosure obligations on any person generating, distributing, or announcing a work with the assistance of AI, requiring a statement of the use of artificial intelligence, identification of the system or application used, and a description of the nature of the human contribution, to be given at the point of recordation, first announcement, commercial distribution, or transfer of rights. The draft bill also expressly prohibits the removal or alteration of AI-use disclosures, the use of artificial intelligence to imitate a particular creator\u2019s distinctive style without consent, and the use of artificial intelligence to create works that infringe moral rights or misrepresent a creator\u2019s identity. Separately, the draft bill\u2019s elucidation confirms that digital content protected as a \u2018Work\u2019 expressly includes non-fungible tokens as a form of blockchain-based digital art.<\/p>\n<p>Given the uncertainty under the current law, it is advisable for AI service agreements in Indonesia to expressly address the ownership of AI-generated output, the treatment of training data rights, and the ownership of any intellectual property developed through the course of the services, rather than relying on the statutory default, which may not reflect the parties\u2019 commercial expectations. With respect to patents, Indonesia has not formally addressed whether AI-generated inventions qualify for patent protection or whether an AI system may itself be recognises as an inventor.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Blockchain technology as such is not specifically regulated in Indonesia, distinct from its use in the crypto-asset trading context described below. The only formal recognition of blockchain as a business activity is its classification under Indonesian Standard Business Classification (Kode Baku Lapangan Usaha Indonesia or \u2018KBLI\u2019) No. 62014 (Blockchain Technology Development Activities) within Indonesia\u2019s standard business classification system, which encompasses companies engaged in the development and implementation of blockchain technology, including smart contracts and the design of blockchain infrastructure. There is no dedicated licensing regime specific to companies operating solely in blockchain development.<\/p>\n<p>Digital assets, by contrast, are subject to a comprehensive and evolving regulatory framework administered primarily by the OJK. Digital financial assets, including crypto assets, are principally regulated under OJK Regulation No. 27 of 2024 regarding the Implementation of Digital Financial Asset Trading, including Crypto Assets, dated January 10, 2025, as last amended by OJK Regulation No. 23 of 2025 regarding the Amendment of OJK Regulation No. 27 of 2024, dated November 10, 2025 (\u2018OJK Reg. 27\/2024\u2019). OJK Reg. 27\/2024 establishes a licensing regime for Digital Financial Asset Trading Providers, comprising Exchanges, Bourses, Clearing Institutions and Custodians. It classifies crypto assets as digital commodities intended for investment rather than as legal tender or a means of payment. Following its 2025 amendment, the regulation also formally recognises digital financial asset derivatives and requires all Digital Financial Asset Trading Providers to register as ESPs.<\/p>\n<p>As a pending development, a Draft OJK Regulation on digital financial asset offerings, published for public consultation in September 2025, would establish Indonesia\u2019s first regulatory framework for initial coin offerings and initial token offerings. In addition, OJK Reg. 27\/2024\u2019s classification of backed and unbacked tokenized assets signals the regulator\u2019s intention to develop a distinct framework for the tokenization of real-world assets.<\/p>\n<p>The general purpose of this framework is to bring the trading of crypto assets within a licensed, supervised financial market structure comparable to that applicable to other commodities, to protect retail investors, and to preserve the Rupiah\u2019s status as Indonesia\u2019s sole legal tender by expressly excluding crypto assets from use as a means of payment.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Search engines are not subject to a dedicated regulatory regime in Indonesia. A search engine is treated as falling within KBLI No. 63122, which covers the operation of websites that use search engines to generate and maintain large databases of internet addresses and content in easily searchable formats, together with related web-portal and digital-platform activities. As an electronic system, a search engine operator is required to register as an ESP with MOCDA under MOCI Reg. 5\/2020, but is not subject to any algorithm-transparency, self-preferencing, or ranking-neutrality obligation specific to search functionality.<\/p>\n<p>E-commerce marketplaces and related platforms are, by contrast, subject to a detailed and recently updated sector-specific regime. MOT Reg. 19\/2026 recognises eight categories of electronic trading organiser business model, including Online Retail, Marketplace, Online Classified Advertisement, Price Comparison Platform, Daily Deals, Social-Commerce, Ride Hailing, and Online Travel Agent. It imposes business licensing, consumer and merchant complaint-handling, advertising, and fair-competition obligations on platforms operating under these models.<\/p>\n<p>Notably, MOT Reg. 19\/2026 imposes a mandatory algorithmic ranking obligation, requiring marketplace, classified-advertisement, daily deals, social-commerce, ride-hailing and online-travel-agent platforms to ensure their search, recommendation, and ranking systems prioritise domestic products, including a requirement that domestic products appear in the first row of the first page of search results, with priority given to products from micro and small enterprises. MOT Reg. 19\/2026 also introduces specific obligations governing the use of AI in e-commerce, including mandatory labelling of AI-generated product content. It further requires foreign platforms that meet specified activity thresholds \u2013 namely, at least 1,000 transactions or shipments to Indonesian consumers, or at least 1% of domestic internet traffic, within a one-year period \u2013 to appoint a representative office domiciled in Indonesia.<\/p>\n<p>The general purpose of this framework is to provide consumer and merchant protection in e-commerce transactions, promote the competitiveness of domestic products and micro and small enterprises within e-commerce platforms, and bring foreign platforms serving the Indonesian market within the scope of domestic regulatory oversight.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a single, dedicated social media law. Social media and online platforms are instead governed by the general electronic systems and content regulation framework, supplemented by specific child protection obligations. The EIT Law applies to social media platforms as ESPs and regulates online conduct, prohibited content, and platform liability, and GR 71\/2019 sets out the corresponding operational and accountability requirements. MOCI Reg. 5\/2020 imposes proactive content moderation duties on platforms, including the obligation to monitor user-generated content and respond to takedown orders issued by MOCDA within prescribed timeframes.<\/p>\n<p>The most significant recent development affecting social media platforms is GR 17\/2025 and its implementing regulation, MOCDA Reg. 9\/2026.<\/p>\n<p>This framework requires electronic system providers, including social media and online platforms, to provide information on minimum age thresholds across five age bands: 3 to 5, 6 to 9, 10 to 12, 13 to 15, and 16 to below 18 years. Providers must also conduct a mandatory self-assessment and risk classification (high or low risk) of each product, service, or feature against defined risk indicators, including contact with unknown persons, exposure to harmful content, consumer exploitation, threats to data security, addictive design, and psychological or physiological harm. Providers must obtain verified parental consent before a child may use a relevant product or service and deactivate accounts of users under 16 years of age on platforms classified as social networking or media services, which are presumptively categorised as high risk under the regulation, unless a different risk profile is established through the self-assessment process.<\/p>\n<p>The framework separately prohibits default profiling of children and the collection of children\u2019s precise geolocation data, except in limited and justified circumstances.<\/p>\n<p>The general purpose of this framework is to bring platform content and conduct within a licensed and accountable electronic systems regime and, most recently, to establish a comprehensive, risk-based child online safety regime addressing age verification, parental consent, and design-level protections for child users.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As with cybersecurity, there is no single online safety statute with a self-contained sanctions ceiling. The applicable maximum sanction depends on which underlying regime is engaged by the relevant conduct. Content-related offences under the EIT Law, such as the dissemination of false, defamatory, or otherwise unlawful electronic information, carry penalties of up to 12 years\u2019 imprisonment and\/or a fine of up to IDR 5 billion. Where a breach also involves the mishandling of personal data, the PDP Law sanctions described above, including an administrative fine of up to 2% of annual revenue and imprisonment of up to six years, may separately apply.<\/p>\n<p>The child-protection-specific regime under GR 17\/2025 and MOCDA Reg. 9\/2026 imposes its own graduated administrative sanctions regime of written warning (limited to two occasions), administrative fine, temporary suspension, and access termination, applied on a cumulative-alternative basis, meaning MOCDA is not required to proceed sequentially and may impose a more severe sanction directly for a serious violation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Indonesia does not have a dedicated law or regulation governing spatial computing, augmented reality, virtual reality, or the metaverse as such. The only formal regulatory touchpoint identified is KBLI No. 26220 (Manufacture of Computer Equipment), which expressly includes immersive media equipment, being virtual reality, augmented reality and mixed reality devices such as virtual reality helmets and augmented reality glasses, as a named subcategory for manufacturing and import classification purposes. However, this is a hardware manufacturing and trade classification rather than a substantive regulatory framework for spatial computing as a technology or service.<\/p>\n<p>In the absence of dedicated regulation, a spatial computing product or service offered commercially in Indonesia would fall within the general electronic systems framework under the EIT Law and GR 71\/2019, requiring ESP registration where applicable. Where a spatial computing device or platform collects biometric data, such as eye-tracking, hand-tracking or spatial-mapping data, such processing would fall within the \u2018specific personal data\u2019 category under the PDP Law, triggering the corresponding heightened consent, data protection impact assessment, and security requirements. A device incorporating wireless or telecommunications connectivity would separately require equipment certification under MOCDA Reg. 3\/2024.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No law, regulation or standard business classification specific to quantum computing has been identified in Indonesia. As with other emerging technologies not yet subject to bespoke regulation, a quantum computing service offered commercially in Indonesia would fall within the general electronic systems framework under the EIT Law and GR 71\/2019.<br \/>\nThe clearest point of likely future regulatory contact is cryptography. BSSN has a general mandate over national cryptographic policy (persandian), and the draft Law regarding Cyber Security and Resilience would formalise BSSN\u2019s authority to establish national cryptographic standards applicable to digital-element products that use cryptographic technology. The draft law would also empower BSSN to require such products to use BSSN-approved or internationally recognised cryptographic standards. No provision specifically addressing quantum computing or quantum cryptography has been identified in either the current legal framework or the draft cybersecurity legislation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Data centre activities in Indonesia are classified under KBLI No. 63102 (Computing Infrastructure Provision, Hosting, and Related Activities), which covers the provision of cloud computing infrastructure, hosting services, data centre colocation, and related data storage services. This business classification is not subject to foreign ownership restrictions.<\/p>\n<p>A data centre business is classified as a medium-to-high-risk business activity under Indonesia\u2019s risk-based licensing regime, requiring the operator to obtain a Business Identification Number and a verified standard certificate. As an industrial activity, the operator must also register with the Ministry of Industry\u2019s National Industrial Information System, which involves a technical verification. A data centre operator must separately register as an ESP with MOCDA under MOCI Reg. 5\/2020 and undergo the BSSN Reg. 8\/2020 self-assessment and risk classification process described above.<\/p>\n<p>On data governance, a data centre operator\u2019s localisation obligations depend on whether it is classified as a public-scope or private-scope ESP under GR 71\/2019, as described in the response to Question 5 above. Certain regulated sectors, including banking and healthcare, impose sector-specific requirements to maintain a data centre and\/or disaster recovery centre within Indonesia.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>First, we anticipate the enactment of Indonesia\u2019s first dedicated cybersecurity statute, the Law regarding Cyber Security and Resilience, which will formalise the Critical Information Infrastructure regime currently found only in presidential regulation, introduce a materially strengthened criminal sanctions regime, and impose new supply chain security and risk-tiered product certification obligations across the technology sector.<\/p>\n<p>Second, we anticipate the finalisation of Indonesia\u2019s first binding, sector-wide instrument on artificial intelligence, through the Draft Presidential Regulation on AI, alongside the completion of the parallel Draft Revised Copyright Law, which is expected to introduce, for the first time, express statutory criteria for the protection of AI-assisted works and to confirm the protection of blockchain-based digital content, including non-fungible tokens, as a category of protected work. Taken together with the recently introduced AI labelling and governance obligations under MOT Reg. 19\/2026, this signals a shift from Indonesia\u2019s current ethics-guideline-based approach to AI toward a more structured, risk-based statutory regime.<\/p>\n<p>Third, we anticipate continued rapid development of the digital asset regulatory framework under the OJK, in particular the finalisation of Indonesia\u2019s first regulatory framework for initial coin offerings and initial token offerings under the pending Draft OJK Regulation on digital financial asset offerings. We also expect further regulatory attention to novel product categories, such as tokenized real-world assets and prediction markets, as OJK continues to test the boundaries of the existing digital financial asset framework against new market entrants.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no sector-specific sustainability or net-zero regulation applicable to the technology sector in Indonesia. No requirement exists, for example, mandating green data centre standards, technology-sector-specific carbon disclosure, or e-waste-specific obligations for technology companies.<\/p>\n<p>Technology companies in Indonesia are subject to Indonesia\u2019s general corporate sustainability disclosure framework in the same manner as any other company. Under OJK Regulation No. 51\/POJK.03\/2017 regarding the Implementation of Sustainable Finance for Financial Service Institutions, Issuers, and Public Companies, dated July 27, 2017 (\u2018OJK Reg. 51\/2017\u2019), a listed technology company, as an issuer or public company, is required to prepare and submit an annual Sustainability Report to the OJK, with content requirements further elaborated under OJK Circular Letter No. 16\/SEOJK.04\/2021 regarding the Form and Substance of the Annual Report of Issuers and Public Companies, dated June 29, 2021 (\u2018OJK CL 16\/2021\u2019).<\/p>\n<p>Separately, Law No. 40 of 2007 regarding Limited Liability Companies, dated August 16, 2007, as last amended by Law No. 6 of 2023 regarding the Enactment of Regulation of the Government in Lieu of Law No. 2 of 2022 regarding Job Creation into Law, dated March 31, 2023 (\u2018Company Law\u2019), requires all limited liability companies, whether listed or unlisted, to disclose in their annual reports their fulfilment of social and environmental responsibilities.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">9965<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/147468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=147468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}