Indonesia is finalising the presidential regulation that would finally create its personal data protection authority, deputy communications and digital minister Nezar Patria said at a US-ASEAN Business Council dinner in Jakarta on 21 July 2026, even as the law that mandates the body sits under materiil review at the Constitutional Court in Case 236/PUU-XXIV/2026.

The Ministry of Communication and Digital, known as Komdigi, published the remarks in press release No. 131/HM-KKD/7/2026 on Wednesday 22 July 2026. According to the ministry, the government is finalising the establishment of a Personal Data Protection Authority that will operate independently, and the deputy minister described the discussion as one of the closing stages in drafting a presidential regulation, or Perpres, targeted for completion in roughly two months.

That timetable would place the instrument in late September 2026. It arrives close to four years after Law No. 27 of 2022 on Personal Data Protection entered into force in October 2022, and nearly two years after the two-year transition period for controllers and processors expired in October 2024. Indonesia has had a data protection statute with criminal sanctions attached to it for longer than it has had anyone empowered to enforce that statute.

An authority outside the ministry that drafted it

The structural question that delayed the body for years concerns where it sits. Nezar Patria addressed it directly. According to Komdigi, the deputy minister said the authority is projected not to sit beneath the ministry, while still running its reporting line to the president through Komdigi.

"This personal data protection body will work independently with its entire structure, but all of its reports are addressed to the president through the Komdigi Ministry," he said, speaking at the US-ASEAN Business Council Dinner Dialogue themed Digital Economy Mission to Indonesia 2026, held at the Mandarin Oriental Hotel in Central Jakarta on Tuesday 21 July 2026. The quotation is translated from the Indonesian text of the ministry release.

The formulation is doing careful work. Full structural independence is asserted; the reporting channel runs back through the ministry that supervises the digital sector and that has itself been the government's principal voice on platform regulation. Whether an authority reporting through a line ministry satisfies the independence standard that data protection regimes elsewhere treat as constitutive is a question the release does not resolve.

It is not an abstract question. Independence has become the load-bearing element in several live disputes across other jurisdictions. Brazil converted its national data protection authority into a full independent regulatory agency under Law 13.848/2019, a status change that expanded its enforcement powers before it set child protection among its 2026 and 2027 priorities. In Ireland, the appointment of a former Meta executive as one of three data protection commissioners drew argument from privacy advocates that effective oversight requires institutional distance from commercial interests, against industry submissions that technical expertise matters more. The same fault line runs through the transatlantic transfer debate, where the European Commission's finding on the United States rests heavily on the independence of the enforcing body.

Two presidential regulations, drafted in parallel

The data protection Perpres is not moving alone. According to Komdigi, the government is simultaneously finalising a presidential regulation on the National AI Roadmap, and the two instruments were drafted in parallel as the foundation of artificial intelligence governance in Indonesia.

"The foundation of AI governance rests on two main aspects, namely AI ethics and personal data protection. Therefore, the preparation of the two Presidential Regulations runs simultaneously so that Indonesia has a regulatory framework that is able to encourage innovation while providing protection to the community," Nezar Patria said.

The pairing is deliberate and it is unusual. Most jurisdictions built data protection law first and bolted AI rules on afterwards, inheriting the seams. Indonesia is attempting both foundations at once, which removes one source of friction and creates another: two instruments that must be internally consistent before either takes effect, drafted by a government that has not yet stood up the institution one of them creates.

On the direction of the AI instrument, the deputy minister was explicit that the intent is permissive. According to the ministry, the government wants AI regulation that adapts to technological development without obstructing innovation, and the roadmap is meant to open space for AI development while giving certainty about the direction of that development.

"We are open to all AI initiatives and innovations that will be developed in Indonesia. The National AI Roadmap is designed to support that innovation, not to restrict it," he said.

Three risk tiers for AI products

The mechanism is familiar. Komdigi stated that the government will apply risk-based regulation in AI governance, under which every AI product will be classified according to risk level, running from low through medium to high.

"Our focus is AI risk mitigation. AI products that carry high risk will of course be regulated more comprehensively than products with low risk. In that way, innovation can keep developing without setting aside security, ethics and public protection," Nezar Patria said.

Three tiers is one fewer than the European Union's structure, which separates unacceptable practices, high risk, limited risk and minimal risk. The European experience with that architecture offers a reference point on how long the high-risk category takes to bed in. Obligations for the most common class of high-risk systems, covering employment screening, credit scoring and biometric identification, were originally set to apply from August 2026, and were subsequently pushed to 2 December 2027, with a second tranche moved to 2 August 2028. The Indonesian release does not state which categories of product will fall into which tier, nor which body will make the classification, nor what obligations attach at each level. Those are the details that determine whether a tiered scheme constrains anything.

The case the court is already hearing

Running underneath the Perpres timetable is litigation the ministry release does not mention.

The Constitutional Court of the Republic of Indonesia registered petition No. 236/PUU-XXIV/2026, a materiil review of Law No. 27 of 2022 on Personal Data Protection, in its electronic constitutional case register at 10:00 WIB on Friday 19 June 2026. The court transmitted a copy of the petition to the president the same day under letter No. 237.236/PUU/PAN.MK/SP/06/2026, signed by acting registrar Wiryanto.

The transmission was not discretionary. According to the court's letter, Article 52 of Law No. 24 of 2003 on the Constitutional Court, as last amended by Law No. 7 of 2020, requires that the court deliver a petition recorded in the constitutional case register to the House of Representatives and the president within no more than seven working days of registration. The court moved on day one. A separate record of service, No. 237.236/PUU/PAN.MK/BASP/06/2026, states that summons officer Rio Tri Juli Putranto delivered the copy to the president's office at Jalan Veteran 17-18, Jakarta, at 13:20 WIB the same afternoon.

Three hours and twenty minutes elapsed between registration and delivery. Copies went to the chief justice and deputy chief justice of the court, the minister of state secretary, the minister of law, the minister of communication and digital, and the cabinet secretary. The letter invites the president to prepare a statement ahead of the hearing at which the court will take testimony from the House and the government.

Neither the letter nor the record of service identifies the petitioner or specifies which articles of the law are challenged. Materiil review tests the substance of statutory provisions against the 1945 Constitution rather than the procedure by which a law was passed, which places the content of the data protection regime itself in question while the executive drafts the instrument that would operationalise it.

What Komdigi told the court

An account of the proceedings in Case 236/PUU-XXIV/2026, published on LinkedIn by data and privacy policy specialist Luis Alberto Montezuma, records the ministry setting out the state of the draft before the court. According to that account, Alexander Saba, director general of digital space supervision at Komdigi, stated that "the draft Presidential Regulation on the Indonesia DPA has gone through the process of planning, drafting, harmonizing and has been submitted to the President through the Letter of the Minister of State Apparatus Empowerment and Bureaucratic Reform dated May 20, 2026."

That detail matters for reading the two-month estimate. If the draft reached the president on 20 May 2026, then by 21 July it had been with the executive for two months already, and the further two months Nezar Patria described would carry the process to roughly four months from submission. The routing through the Ministry of State Apparatus Empowerment and Bureaucratic Reform, the ministry responsible for the structure and staffing of state bodies, is consistent with an instrument that creates a new institution rather than one that merely sets rules.

The ministry release and the court account do not conflict, but they measure from different points, and neither states a fixed date.

Four years of statute without a regulator

The compliance position this leaves is unusual. Indonesia's law carries obligations on controllers and processors, and criminal provisions attach to certain misuses of personal data, yet the supervisory body contemplated by the statute does not exist. Complaints have nowhere institutional to go. Cross-border transfer assessments have no domestic authority to notify. Sanctions have no issuing office.

Comparisons with mature regimes cut in both directions. Enforcement volume in Europe is high and its durability is contested: a Luxembourg court annulled Amazon's 746 million euro penalty and returned the case to the regulator on the basis that the authority had not properly assessed fault, and analysis of the wider record found that close to 40 percent of the 7.1 billion euros in announced GDPR fines have been annulled or are under active challenge. Capacity is also strained. The European Data Protection Board asked the European Commission on 17 July 2026 for a legal basis allowing regulators in different fields to exchange confidential information, citing a rise in complaint volume driven partly by AI use against authorities that collectively receive more than 100,000 complaints a year.

A new authority starting in 2026 inherits none of that case history and none of that institutional muscle. It also inherits none of the precedent that makes enforcement stick.

Why the marketing sector outside Indonesia has an interest

Indonesia is the largest digital market in Southeast Asia, and the regulatory posture it settles on will shape how global platforms and their advertising partners handle Indonesian user data. The country has shown willingness to act unilaterally on platform access before. Authorities blocked DuckDuckGo in August 2024 over gambling and pornographic content reachable through the service. More recently, a government regulation identified as PP Tunas prompted YouTube to warn that users under 16 in Indonesia may lose the ability to log in, a change the platform framed as compliance rather than commercial choice and for which it gave no effective date.

Audience conditions in the region are shifting at the same time. Chartbeat measurement of publisher traffic recorded Southeast Asia losing five percentage points of search-driven pageviews in the second quarter of 2026 while social platforms rose to 26 percent from 19 percent. Discovery is moving toward platforms whose personalisation depends on exactly the processing a data protection authority would supervise.

For agencies and platforms running campaigns into Indonesia, the practical variable is not the existence of the law, which has been in force since 2022, but the arrival of a body that can interpret it, issue guidance and impose consequences. Consent standards, legitimate interest reasoning, transfer documentation and retention practice all currently operate against statutory text without regulatory gloss. Ecuador's regulator, by contrast, set out detailed conditions for legitimate interest processing, including limits where automated profiling produces significant effects, giving controllers something concrete to test their practices against.

The AI roadmap carries a parallel implication. If Indonesian rules classify advertising personalisation, creative generation or automated bidding tools by risk tier, the classification will determine documentation and transparency burdens for technology vendors serving the market. British regulators have already warned that agentic AI is running in production systems and needs oversight frameworks now, and the European Union has published labelling icons for AI-generated content ahead of its August 2026 transparency deadline. Indonesia has stated a direction without yet publishing the text that gives it effect.

Infrastructure alongside regulation

Beyond the two instruments, Komdigi stated that the government continues strengthening the national AI ecosystem through digital infrastructure construction, data centre development, increased computing capacity and digital talent development.

"The combination of adaptive regulation, strong personal data protection and support for innovation will be important capital for Indonesia in accelerating digital economic growth and strengthening competitiveness at the global level," Nezar Patria said.

The release provides no figures for any of the four infrastructure commitments, no timeline for the data centre or compute expansion, and no funding source. It also gives no date for the AI roadmap Perpres, only that it is being finalised alongside the data protection instrument.

What remains open

Several elements are unresolved on the record available. The composition and appointment mechanism for the authority's leadership are not described. Its budget line is not identified. The relationship between an authority reporting through Komdigi and sectoral supervisors that already handle data in banking, health and telecommunications is not addressed. Nor is there any indication of how the pending constitutional challenge might interact with an instrument drafted under the statute now being reviewed.

The materiil review adds a variable the executive cannot control. Should the Constitutional Court alter the interpretation of provisions in Law No. 27 of 2022, a presidential regulation issued in September would be operating against a statute whose meaning had shifted underneath it. The court has not published a hearing date, and the letter to the president describes the proceedings as pending notification and summons.

Two documents, issued a month apart by different branches of the Indonesian state, describe the same law from opposite ends. One sets a timetable for building the institution it requires. The other opens the question of whether parts of it survive review.

Timeline

Summary

Who: The Ministry of Communication and Digital of Indonesia, known as Komdigi, through deputy minister Nezar Patria, alongside director general of digital space supervision Alexander Saba, and the Constitutional Court of the Republic of Indonesia, whose acting registrar Wiryanto signed the transmission of petition No. 236/PUU-XXIV/2026 to the president.

What: The government is finalising a presidential regulation establishing a Personal Data Protection Authority that would operate independently with its own structure while reporting to the president through Komdigi, drafted in parallel with a presidential regulation on the National AI Roadmap that applies risk-based regulation across three tiers of AI product. Separately, Law No. 27 of 2022 on Personal Data Protection is under materiil review at the Constitutional Court.

When: The remarks were delivered on Tuesday 21 July 2026 and published on Wednesday 22 July 2026 in press release No. 131/HM-KKD/7/2026, with the presidential regulation targeted for completion in roughly two months. The constitutional petition was registered at 10:00 WIB on Friday 19 June 2026 and served on the president at 13:20 WIB the same day. The draft regulation reached the president on 20 May 2026.

Where: The statements were made at the US-ASEAN Business Council Dinner Dialogue themed Digital Economy Mission to Indonesia 2026, held at the Mandarin Oriental Hotel in Central Jakarta. The petition copy was served at the presidential offices at Jalan Veteran 17-18, Jakarta 10110.

Why: Indonesia has had a personal data protection statute in force since October 2022 without the supervisory authority the law contemplates, leaving controllers, processors and advertising technology vendors operating against statutory text with no regulator to interpret it, issue guidance or impose sanctions. The parallel AI roadmap sets the classification framework that will determine documentation and transparency burdens for AI products sold into the market.