Tunas Akara
Back to Blog

UU PDP Fines Changed Under the New KUHP: Smaller Numbers, Same Obligations

by RayhanUpdated 6 min read
uu-pdpdata-protectioncomplianceindonesia
UU PDP Fines Changed Under the New KUHP: Smaller Numbers, Same Obligations

UU PDP Fines Changed Under the New KUHP: Smaller Numbers, Same Obligations

UU PDP's criminal fines went down, not up. Don't read that as good news too fast — the sanctions most SMEs actually face didn't change at all.

On January 2, 2026, Indonesia's criminal-code adjustment law, UU No. 1/2026 on Penyesuaian Pidana, took effect and quietly rewrote the criminal fines inside dozens of sectoral laws, UU PDP (the Personal Data Protection Law) among them. The nominal fines written into UU PDP's criminal articles dropped, in some cases sharply.

Hukumku.id's analysis traces the specific numbers, and they're worth understanding correctly before assuming what they mean for a business.

What actually changed

UU PDP's criminal fines were originally written as fixed rupiah amounts. Pasal 67 ayat (1) and (3), covering unlawfully obtaining or using someone else's personal data, each carried a maximum fine of Rp5 billion. Pasal 67 ayat (2), unlawfully disclosing personal data, carried Rp4 billion. Pasal 68, falsifying personal data, carried Rp6 billion.

Think of it like a currency redenomination: the number on the bill changes, but the real value behind it adjusts through the same formula for everyone. Under the new KUHP's categorical system, set out in Pasal 79 of UU No. 1/2023, fines no longer live as one-off numbers inside each law. They map onto eight standard categories, from Category I (Rp1 million) up to Category VIII (Rp50 billion), and the conversion follows the maximum prison term attached to the same offense: three to five years converts to Category IV (Rp200 million), five to eight years converts to Category V (Rp500 million).

Applied to UU PDP, Pasal 67's four-to-five-year maximums land each of its three clauses in Category IV, and Pasal 68's six-year maximum lands in Category V. In practice, Rp4-6 billion became Rp200-500 million. That conversion mechanism is independently documented in commentary on the new fine categories, and the underlying law's effective date is confirmed by reporting on its signing.

This isn't specific to UU PDP. The categorical system exists so lawmakers don't have to amend hundreds of individual statutes every time inflation makes an old fine meaningless, and Indonesia used the Penyesuaian Pidana law to apply it across the board. UU PDP just happens to be one of the laws where the drop is large enough to notice.

Why the smaller number shouldn't change how an SME behaves

A criminal fine requires a prosecutor, a court, and proof of intent, "dengan sengaja dan melawan hukum" in the statute's own language. Most data-handling failures at an SME never clear that bar.

What clears it far more easily, and far more often, is administrative enforcement, which UU PDP's Pasal 57 keeps entirely separate from the criminal chapter and which this recalibration doesn't touch. The supervisory authority can issue a written warning, order a temporary suspension of processing activities, order deletion or destruction of the data in question, or impose an administrative fine of up to 2% of annual revenue.

For most SMEs, 2% of revenue is a materially larger number than a Category IV criminal fine, and a suspended processing activity — meaning a payment system, a booking platform, or a customer database taken offline — is a worse outcome than either.

Loading diagram…

What this means for posture, not paperwork

None of this is legal advice, and a live case still needs a lawyer who can read the specific facts. What it does argue for is treating UU PDP compliance as an engineering discipline rather than a document filed once.

  • Keep a real data inventory. Know which systems hold personal data, why, and under what legal basis. You can't answer "was this processing lawful" without first knowing what's being processed.
  • Keep consent and legal-basis records where you can produce them fast. A supervisory request answered in a day looks different from one answered after three weeks of searching through Slack.
  • Write a breach runbook before you need one. Who gets notified, in what order, what gets logged, and who has authority to talk to the regulator. I've written about the wider discipline of running vendor-built systems with this kind of structure in a playbook for SME software projects: the same instinct, control through visibility rather than after-the-fact scrambling, applies here.
  • Put data-handling terms in every processor contract. If a vendor touches your customers' personal data, your exposure includes what they do with it. A short clause specifying retention, deletion, and breach notification obligations is cheap insurance against a supervisory finding.

The takeaway

The nominal criminal fine in UU PDP went down, not up, and treating that as good news misreads what changed. Prosecutors always needed intent and a court to collect that fine, which is exactly why it was never where most SMEs' real exposure sat.

The administrative powers that were always more likely to apply — suspension, forced deletion, a fine tied to revenue rather than a fixed cap — didn't move at all. Build the posture for those, and the criminal number becomes close to irrelevant either way.

Related Posts

Building something similar?

Hotel Management System Development

Custom ERP-style hotel management software: bookings, room status, invoicing, staff, and WhatsApp automation — built around how your hotel actually runs.

See how I can help