Foreign companies must operate via PT PMA (foreign investment company). Requires BKPM approval, minimum capital, and at least 1 local shareholder in some sectors.
Tax & Regulatory // Indonesia
Entity type: PT PMA (Perseroan Terbatas Penanaman Modal Asing)
Core Compliance
Regulatory Vectors
Otoritas Jasa Keuangan (OJK) regulates all financial services. P2P lending, payments, and investment products require OJK licence — lengthy and complex process.
Personal Data Protection Bill (PDPB) enacted 2022. Requires data processing agreements, breach notification within 14 days, and DPO appointment for large processors.
Government Regulation 71 requires strategic data (government, public interest) to be stored in-country. Enforcement active for government-facing products.
Key Legislation
Comprehensive data protection law enacted 2022 with 2-year implementation period.
Electronic system and data localisation requirements for public electronic systems.
IT-based lending services regulation (P2P fintech).
ID has the most complex regulatory environment in SE Asia for foreign tech entrants. Engage a local Indonesian law firm before committing to market entry. A trusted local partner dramatically reduces regulatory risk and timeline.
Regulatory Flashpoints — Evidence Base
Indonesia PDP Law obligations on consent, rights, and processing controls.
Needs human review