Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty
Government Regulation No. 71 of 2019 (PP PSTE), Pasal 3, 23, 24(1)-(2), 31, 32, 39, 40
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 10 October 2019.
A security baseline statutes rule binding public and private bodies.
As of 16 September 2026.
What it requires
- This binds every Electronic System Operator under Indonesian law, whether a government body (Penyelenggara Sistem Elektronik Lingkup Publik) or a private business (Penyelenggara Sistem Elektronik Lingkup Privat), with no sector or size gate.
- Operate your Electronic System reliably and securely, and take legal responsibility for it operating as it should.
- Secure your Electronic System's components, and have and run procedures and means to protect the system against disruption, failure, and loss.
- Provide a security system covering procedures and technical measures, such as antivirus, anti-spam, a firewall, intrusion detection or prevention, or an information security management system, to prevent and counter a threat or attack against your Electronic System.
- Protect your users and the wider public from harm caused by the Electronic System you operate, and provide, train, and equip personnel tasked with and responsible for securing the system's facilities and infrastructure.
- Where you operate an Electronic Agent, an automated device that carries out an action on Electronic Information for a user without that user's direct intervention, such as an automated transaction or e-commerce system, additionally run a standard operating procedure meeting six security-control principles for user data and Electronic Transactions: confidentiality, integrity, availability, authenticity, authorization, and non-repudiation, and test a transacting user's identity and authorization before completing the transaction.
- A violation of Articles 23, 24, 31, 32, 39(2), or 40 can draw an administrative sanction from the Minister, a written warning, an administrative fine of an amount this Government Regulation does not itself fix, temporary suspension, access termination, or removal from the Electronic System Operator registry; the Article 100 sanction list does not name Article 3 itself.
If you get it wrong
Criminal exposureNo
Criminal exposure note
Article 100(5) states that an administrative sanction under this Government Regulation does not extinguish criminal or civil liability, but this Government Regulation does not itself create a criminal offense for failing to secure an Electronic System; that exposure, if any, arises under a different statute such as the Electronic Information and Transactions Law's unauthorized-access offense, already this jurisdiction's scraping-topic finding.
Who enforces it
Enforcement body
The Minister who administers government affairs in the field of communications and informatics (Menteri Komunikasi dan Informatika, since renamed the Ministry of Communication and Digital Affairs / Komdigi), who imposes any of Article 100(2)'s five administrative sanctions.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Every Electronic System Operator, government or private, must operate its Electronic System reliably and securely and is legally responsible for its proper operation. It must secure the system's components and have and run procedures and means to protect the system against disruption, failure, and loss. It must also provide a security system with prevention and countermeasure procedures against a threat or attack that causes such disruption, failure, or loss.
It must protect its users and the public from harm the system causes, and provide, train, and equip personnel responsible for securing the system's facilities and infrastructure. An operator running an Electronic Agent, an automated device carrying out actions on Electronic Information for a user, must additionally run a standard operating procedure meeting six security-control principles for user data and transactions. That operator must also test a transacting user's identity and authorization before completing a transaction.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product