SOVEREIGNTY LAW ATLAS — ID
Indonesia
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04Indonesia's posture shifted from broad localization toward transfer-control — but public-service and financial workloads still face hosting expectations; check the sector, not just the statute.
ATLAS RECOMMENDATION — DOCUMENTED CONTROL · Sectoral localization heritage — on-premises by default. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
The PDP Law (UU 27/2022) is the comprehensive baseline: cross-border transfers require an adequacy-style finding that the recipient country's protection is equal or higher, falling back to consent or contract if not.1 Alongside it, PP 71/2019 governs electronic system operators: public-service ESOs were required to host in Indonesia, while private ESOs may host abroad subject to access duties for authorities.2 The localization edge is sectoral and narrowing — but not gone.
D2 — AI-specific regulation
No binding AI statute. Kominfo Circular Letter 9/2023 issues AI ethics guidance (values, accountability, security) without legal force.3 Sectoral regulators (OJK for financial AI) may act first.
D3 — Cloud & procurement sovereignty
Government and public-service workloads inherit PP 71's hosting expectations; the financial sector operates under OJK rules that have historically required in-country or OJK-accessible hosting for banks. There is no certification scheme; compliance is assessed case-by-case.
D4 — Export & access
Indonesia sits outside Five Eyes and the major access alliances. The practical external exposure is again provider-level: US-controlled cloud providers operating in Indonesia remain within CLOUD Act reach, while domestic-provider localization has been a policy theme across sectors.
Extraterritorial exposure
US lawful-access exposure tracks provider control, as elsewhere. Indonesia's own rules add a second axis: government access duties for authority requests apply to ESOs hosting Indonesian data regardless of where it sits. Dossier drafted from the official Indonesian text; fine-grained analysis of subordinate regulations pending translation review. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied. Indonesian-language sources are summarized in English; the official text governs.
- UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi — JDIH BPK RI — vault
atlas-vault/id/id-pdp-law/2026-08-04.pdf(official Indonesian), sha256ed952dea…, captured 2026-08-04. (VERIFIED) ↑ - PP No. 71 Tahun 2019 — JDIH BPK RI — not vaulted (capture pending). (REPORTED) ↑
- Kominfo Circular Letter No. 9/2023 — JDIH Kominfo — not vaulted (HTML source). (REPORTED) ↑
The instruments.
3 ON RECORD · 2 GAPSUndang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (PDP Law)
VERIFIEDatlas-vault/id/id-pdp-law/2026-08-04.pdf · SHA256 ed952dea… · CAPTURED 2026-08-04Peraturan Pemerintah No. 71 Tahun 2019 — electronic systems and transactions (ESO registration, hosting)
REPORTEDKominfo Circular Letter No. 9/2023 — AI ethics guidance
REPORTEDNo binding AI-specific statute; ethics circular only
No material export/access regime identified at demo depth
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.