Electronic Information and Transactions Law, unauthorised access
Law No. 11 of 2008, Article 30 jo. Article 46, Electronic Information and Transactions Law
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 April 2008.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not access a computer or electronic system belonging to another person in Indonesia without right, including to obtain electronic information or documents from it.
- A separate, higher penalty tier applies where access involves violating, breaking through, exceeding, or breaching a security system that restricts access by user classification or authorisation level.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Article 46 makes each paragraph of Article 30 a separate offence: paragraph (1) up to 6 years' imprisonment and/or a fine of up to Rp600,000,000; paragraph (2) up to 7 years and/or Rp700,000,000; paragraph (3), access that defeats a security system, up to 8 years and/or Rp800,000,000.
Penalty structure
Article 46 sets three escalating fixed caps keyed to which paragraph of Article 30 is violated: up to 6 years' imprisonment and/or a fine of up to Rp600,000,000 for paragraph (1) (simple unauthorised access), up to 7 years and/or Rp700,000,000 for paragraph (2) (access with intent to obtain electronic information or documents), and up to 8 years and/or Rp800,000,000 for paragraph (3) (access that violates, breaks through, exceeds, or breaches a security system). The cap recorded here is the paragraph (3) ceiling, the highest of the three.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- IDR
- Fixed cap
- 800,000,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 30 prohibits three escalating acts, each without right or unlawfully: paragraph (1) accessing another person's computer or electronic system by any means; paragraph (2) the same access with intent to obtain electronic information or documents; and paragraph (3) the same access carried out by violating, breaking through, exceeding, or breaching a security system, defined in the official elucidation as a system that restricts or prohibits computer access based on user classification and authorisation level.
Paragraphs (1) and (2) carry no textual requirement that any security measure be defeated, so a plain reading does not on its own resolve whether reading a public, unauthenticated page is access "without right"; this article has not been amended by the 2016 or 2024 amendments to the Law. Article 46 sets the corresponding criminal penalties.
When LexLint raises it
crawls_webtrains_models