It usually starts small. A call from an unknown number that uses your full name. A message that knows your mother's maiden name. Or a notification from a service you never signed up for.

Your data is in the hands of someone who has no right to it. The reasonable next question: report it where?

In Indonesia the answer is currently more convoluted than it should be, and it helps to know why before you start.

The body that should handle this doesn't exist yet

Law No. 27 of 2022 on Personal Data Protection mandates a supervisory authority reporting directly to the President. That body was meant to receive complaints, investigate, and impose sanctions.

As of August 2026 it has not been established. The Presidential Regulation creating it is still in process, and its absence has been taken to the Constitutional Court.

What this means for you. Your rights under the PDP Law apply in full, the compliance transition period ended in October 2024. What's missing is a single address to complain to. For now, oversight sits with the Ministry of Communication and Digital Affairs, and the criminal route through the police remains open.

Secure things first, report second

This order often gets reversed. Reporting matters, but the process moves slowly, while your data is already circulating today. Secure what can still be secured first.

Change the passwords that matter

Start with your primary email, since nearly every other account recovery runs through it. Don't reuse the same password across services, see the guide to strong passwords.

Turn on two-step verification

This is what makes a leaked password no longer enough to get in. Prefer an authenticator app over SMS, since phone numbers are frequently part of the leak themselves.

Gather evidence before it disappears

Screenshots of suspicious messages, sender numbers, dates and times, and any official notice. This evidence determines how strong your report is, and conversations often delete themselves.

Expect a second wave

Leaked data makes the next scam far more convincing, because the caller already knows your name, address, and history. Treat every call and message claiming to be from your bank as suspect, see the mobile banking security guide.

Three routes, for three different problems

The most confusing part: all three get mentioned together, though they answer different questions.

RouteWhat it's forWhat to reasonably expect
The data controller (the organisation that leaked it) Requesting explanation, deletion, and correction An account of what was affected; a written trail
Ministry of Communication and Digital Affairs Complaints about data protection breaches Scrutiny of the data controller
Police Cyber Crime Directorate Fraud, extortion, account takeover A police report; criminal proceedings

Start with the first row. It sounds counterintuitive, complaining to the party that leaked your data, but the PDP Law places the obligation precisely there, and their written answer becomes material for the other two routes.

What they must do, not merely what's polite

Article 46 of the PDP Law sets a 3x24 hour limit from the moment a breach is discovered. Within that window, the controller must notify the data subject and the supervisory authority, covering at minimum:

  • which personal data was exposed;
  • when and how the breach occurred;
  • the handling and recovery underway.

If you learned about the breach from the news rather than from them, that alone is worth naming in your complaint.

Your other rights, access, correction, erasure, and withdrawal of consent, apply at all times, not only after a breach. The detail is in the guide to the PDP Law.

Writing a complaint that's hard to ignore

A tidily written complaint is much harder to pass over. Include, in order:

  • Your identity as the data subject, and your relationship to the service (customer number, registered email).
  • A dated timeline. When you noticed, how, and what followed.
  • The data affected, as specifically as you know it.
  • The loss you suffered, including loss that isn't yet monetary, time spent, accounts recovered, repeated disruption.
  • A clear request. A written explanation, deletion, or an investigation. A complaint with no concrete request easily stops at being filed.
  • The evidence you gathered earlier.

Keep a copy of every letter and its receipt. If you later pursue compensation, this file is what it rests on.

If you're the one holding other people's data

This side is often overlooked. A café, clinic, boarding house, or shop that collects customer details, even through a guest Wi-Fi form, stands as a data controller, with exactly the same obligations, including that 3x24 hour deadline.

Two things reduce the risk most, and neither costs much:

The responsibilities attaching to network owners are covered separately in the guide to Wi-Fi owner responsibilities.

How well this actually works

Honestly: while the supervisory authority remains unformed, individual complaints rarely produce visible sanctions. That's a reality worth knowing up front.

Even so, reporting isn't wasted effort. A recorded complaint builds the official trail needed if the matter proceeds, and the volume of complaints against a single controller is the thing most likely to trigger scrutiny.

In short

Secure your accounts today, gather evidence before it vanishes, then put a written request to the party that leaked your data. Escalate to the ministry if they ignore it, and to the police once actual fraud has occurred.

Your rights already apply in full. What's still missing is the body to enforce them, and until it exists, a careful paper trail is the tool you can most rely on.

Frequently asked questions

Where do I report a personal data breach right now?

As of August 2026, the supervisory authority mandated by the PDP Law has not been established. In the meantime, complaints go to the Ministry of Communication and Digital Affairs as the digital-space regulator. If there are signs of a crime such as fraud or extortion, report to the Cyber Crime Directorate of the Indonesian National Police.

How quickly must a company tell me my data leaked?

Article 46 of the PDP Law requires data controllers to notify both the data subject and the supervisory authority within 3x24 hours of becoming aware of a breach. That notice must state which data was affected, when it happened, and what is being done about it.

Can I claim compensation?

The PDP Law opens that route. Data subjects may sue for damages arising from unlawful processing of their personal data. Note that this route requires proving loss, so the evidence you gather early determines a great deal. This isn't legal advice, for your own case, consult a lawyer.

My data was part of a large publicised breach. Do I still need to file my own report?

Yes, if you suffered direct consequences such as attempted fraud or an account takeover. Collective reporting addresses the problem at the controller level, while your report documents the loss you personally suffered, and that is what a compensation claim later depends on.