Written for Indonesian CIOs, compliance leads, and regional CTOs whose stack spans Singapore + Jakarta. Anchored to publicly available regulatory texts: UU PDP No. 27/2022, POJK No. 11/POJK.03/2022, Perpres No. 82/2022, and Permenkominfo No. 5/2020. This article is informational, not legal advice — production-line decisions warrant a sign-off from licensed Indonesian counsel.
The regulatory facts you actually have to plan around
Four instruments drive Indonesian data planning today:
-
UU PDP No. 27/2022 (Personal Data Protection Law) — promulgated 17 October 2022, with a two-year transition window. Full enforcement has been live since 17 October 2024. Codifies controller / processor distinctions, lawful bases for processing (Art. 20), the controller’s accountability obligation (Art. 24), the obligation to keep records of all personal-data processing activities (Art. 31), the 3 × 24-hour (72-hour) breach-notification window to both the data subject and the supervisory authority (Art. 46), and DPO appointment expectations for large-scale or sensitive processing. Administrative sanctions reach up to 2% of annual revenue.
-
PSE registration regime under Permenkominfo No. 5/2020 — any Private-Scope Electronic System Operator (PSE Lingkup Privat), foreign or domestic, that delivers services to or from Indonesia must register with Kominfo (now Komdigi). The enforcement deadline was 21 July 2022, and access-blocking sanctions under Article 7 are real: PayPal and Yahoo Search were briefly blocked in July 2022; Kominfo notified six online travel agents in March 2024; and in June 2025 Komdigi cut off bathandbodyworks.com (PT Dunia Luxindo), eBay Inc. and KLM Royal Dutch Airlines for non-registration.
-
Sector-specific data localization — finance — POJK No. 11/POJK.03/2022 (“Implementation of Information Technology by Commercial Banks”, effective 7 October 2022) governs IT governance, risk management, cybersecurity and outsourcing for commercial banks. It is the regulation that ties offshore processing of certain workloads to prior OJK approval — “everything in Indonesia” is not the rule, but cross-border placement requires a documented case.
-
Critical / vital information infrastructure — BSSN — Perpres No. 82/2022 on the Protection of Vital Information Infrastructure (IIV) designates BSSN as the coordinating authority and names eight strategic sectors: government administration, energy & mineral resources, transportation, finance, health, ICT, food, and defense. Operators in these sectors face additional identification, protection-framework, capacity-building, maturity measurement and incident management obligations under BSSN’s derivative regulations.
“All data must be hosted in Indonesia” is not universally true — but it is materially true for regulated finance and for IIV-designated operators. Mis-applying the broad version of this rule costs money; misreading it where it really binds costs jobs.
What this means for your backup architecture
A defensible 2026 backup architecture for an Indonesia-serving business satisfies four properties simultaneously:
| Property | Why |
|---|---|
| Primary backups in Indonesia (or onshore-equivalent with documented basis) | POJK 11/2022 offshore approval gate + Perpres 82/2022 IIV obligations |
| Immutable / ransomware-proof snapshots | UU PDP Art. 46 breach-notification clock + OJK-style audit expectations |
| Per-user / per-system access logs | UU PDP Art. 24 (controller accountability) + Art. 31 (processing records) |
| Documented cross-border replication (if any) | UU PDP cross-border transfer regime + DPA disclosure to data subjects |
If your current architecture is “we copy to AWS S3 in Singapore” with no documented basis, you have work to do. Not impossible work — but work.
The 2026 backup-and-restore checklist
Practical list to take into your next quarterly review:
- We can name the physical Indonesian region where production backups land
- Backups are immutable for the retention period (regardless of admin privileges)
- We can produce a point-in-time restore to within 1 hour for every Tier-1 system
- We have tested a restore in the last 90 days, with timestamped evidence
- Cross-border replication (if any) is documented in the DPA shown to data subjects, with a lawful basis under UU PDP Art. 56
- Access logs to backup data are retained for ≥ 1 year and tied to named identities (not shared accounts) — required by UU PDP Art. 24 + Art. 31
- Backup retention policies match the legal hold requirements for our sector (FS: 7 yrs commonly; healthcare: longer)
- We have a breach-notification runbook that names individuals and respects the 3 × 24-hour (UU PDP Art. 46) window to data subject + supervisory authority
- If we are a commercial bank or an IIV operator, our offshore placement has a POJK 11/2022 OJK approval or a documented BSSN-aligned posture
- We have a named Data Protection Officer (or a documented decision that one is not required) — UU PDP encourages a DPO for large-scale or sensitive processing
How TWO TWO BaaS solves this for you
We built TWO TWO BaaS specifically because the generic global backup products don’t make these properties easy to verify under Indonesian scrutiny. By default:
- Primary backups land in Singapore (Azure Southeast Asia) or Jakarta (Azure Indonesia Central, opt-in)
- Snapshots are immutable for the retention window (anti-ransomware)
- Per-restore actions logged to a tamper-evident audit log retained 1 year — aligned to UU PDP Art. 24 + Art. 31
- Restore testing is included (no per-restore fee) so your team can actually exercise the runbook quarterly
- A breach-notification runbook template aligned to the 3 × 24-hour Art. 46 window ships with the service
The backup engine is built by Jumborca; TWO TWO operates the Singapore tenancy, owns the SLA, and provides the local compliance documentation.
How to start
If you’re a CIO in Jakarta, KL, or Singapore with workloads that touch Indonesian customers, the right first step is 30 minutes — not a procurement cycle. We’ll go through the checklist with you, pointing out which items will fail an audit if attempted today.
Apply for a TWO TWO BaaS 30-day trial or book a discovery call.
If you are evaluating a data, backup, or AI project in Malaysia or Indonesia, we can spend 30 minutes helping you assess the compliance boundary, the system path, and the scope of the first delivery phase.
