Sheila Thomas Law Office
Language
EN ID ZH
Search
Publications

Insights For Business Decisions

Practical perspectives on the legal and commercial decisions behind technology deployment, data use, distribution architectures, and cross-border transactions.

Sheila Thomas Law Office Recognised in Inaugural ALB Asia Top Cybersecurity & Data Law Firms 2026
Firm News • Aug 26, 2026

Sheila Thomas Law Office Recognised in Inaugural ALB Asia Top Cybersecurity & Data Law Firms 2026

Jakarta, August 2026- Sheila Thomas Law Office has been recognised in Asian Legal Business (ALB)’s inaugural Asia Top Cybersecurity & Data Law Firms 2026, published in the August 2026 edition of ALB Asia.For businesses, cybersecurity and data issues increasingly sit inside bigger commercial decisions: Can we deploy the technology? Can data move across borders? Will the customer sign? Can we pass enterprise due diligence? And who bears the risk when something goes wrong?“Clients rarely come to us with a compliance question in isolation. They come with a business decision: can we launch, can we sign, can the data move, can the AI act, and what risk are we taking? Our role is to help make those decisions commercially workable and legally defensible.” Sheila Thomasyadi, Founder & PartnerThe recognition reflects Sheila Thomas Law Office’s work at the intersection of technology, data privacy, cybersecurity and commercial transactions, including technology and SaaS and cloud contracts, agentic AI deployment and contracting, cross-border data transfers, privacy documentation, enterprise customer requirements, and regional commercial arrangements.Our work does not stop with technology and data. The firm also advises Indonesian and international businesses on distribution, reseller and OEM arrangements, strategic financing, commercial loans and cross-border commercial transactions, including transactions involving tangible products.This combination matters because technology, data and commercial risk rarely operate separately. A product may need to satisfy customer security requirements before it can be sold. An AI deployment may require contractual limits on authority and responsibility. A regional expansion may involve technology contracts, data transfers and distribution arrangements at the same time.

Read Article →
What 2026's Regulatory Cluster Means for Buyers, Sellers, and Dealmakers
Corporate Law • Aug 12, 2026

What 2026's Regulatory Cluster Means for Buyers, Sellers, and Dealmakers

Indonesia has long been one of Southeast Asia's most attractive investment destinations — a market of nearly 290 million people, GDP growth hovering near 5%, and a growing middle class. But attractiveness on paper has never been the hard part of doing deals in Indonesia. Execution has. Over the past year, a cluster of regulatory changes has reshaped how commercial structuring, M&A, and cross-border transactions actually get done — and dealmakers who are still working from 2023 or 2024 precedents are operating with an outdated playbook.This piece walks through the current state of Indonesian deal structuring: how foreign ownership rules have shifted, why corporate criminal liability is now a first-order transactional issue, what a new mandatory compliance regime means for due diligence, and how experienced dealmakers are adapting pricing, indemnities, and deal documents in response.1. The 2025–2026 Regulatory Cluster, at a GlanceRather than arriving as a single reform package, the changes reshaping Indonesian dealmaking came from several overlapping instruments issued by different institutions over roughly a twelve-month window:Omnibus Law amendments, updating the foreign investment framework (the former Negative Investment List, now reframed as an Investment Priority List) and adjusting PT PMA (foreign investment company) capital and notification requirements.Law No. 1 of 2026, formalizing corporate criminal liability and aligning sentencing with the new Criminal Code.Ministry of Law and Human Rights Regulation No. 49 of 2025 ("Permenkum 49/2025"), introducing a mandatory company compliance assessment regime for Indonesian limited liability companies.The new Criminal Code (KUHP), which took effect on 2 January 2026, replacing the colonial-era criminal code and expanding corporate offense provisions.KPPU Regulation No. 3 of 2023, which had already overhauled merger notification thresholds and extended the competition authority's reach to foreign-to-foreign transactions, continues to interact with these newer instruments.Minister of Finance Regulation No. 1 of 2026 ("PMK 1/2026"), issued 22 January 2026, revising tax treatment for restructurings, including the use of book value in mergers, demergers, and asset transfers involving state-owned enterprises.No transaction signed or closed from early 2026 onward can be structured without accounting for this cluster — and deals papered in 2025 but not yet closed warrant a fresh look, particularly around compliance representations and criminal exposure warranties.2. Foreign Ownership and Entry Structures: What's Actually ChangedIndonesia's foreign ownership rules continue to be organized around a sectoral classification system. The Omnibus Law amendments replaced the old negative list with a risk-based licensing framework, sorting business activities into priority, open, and restricted categories. Priority sectors are generally open to full foreign ownership through a PT PMA and may carry fiscal incentives; other sectors — including several in media, telecommunications, logistics, and domestic trade — retain foreign equity caps commonly set at 49%, 67%, or 95% depending on the activity. Every deal still needs a line-by-line check of the target's business classification code against the current schedules before structuring even begins.Common entry and deal structures in the region typically fall into three categories: direct share acquisition through an intermediate holding company (commonly in Singapore or Hong Kong), joint ventures in markets with foreign ownership limits, and asset purchases where a share deal is legally or structurally complicated. Indonesia, alongside Vietnam and the Philippines, remains one of the markets where joint ventures are most frequently used to navigate ownership restrictions.For structuring purposes:PT PMA incorporation or conversion. A local PT can convert to a PT PMA following a foreign share acquisition, subject to notification to Indonesia's investment ministry (BKPM) and sectoral clearance.Joint ventures. Where caps apply, the JV agreement needs careful attention to governance, deadlock resolution, put/call options, and exit mechanics that will actually hold up under Indonesian corporate law.Nominee arrangements remain off the table. These structures continue to carry significant legal risk in Indonesia and were not validated by the recent reforms — a point worth repeating given how often it still comes up in early-stage deal conversations.Share deals vs. asset deals. Share acquisitions dominate Indonesian M&A because asset transfers can trigger the loss of operating permits tied to the selling entity, along with separate tax exposure. Where a target carries significant contingent liabilities or an uneven compliance record, however, an asset deal may offer cleaner risk separation — worth modeling early rather than defaulting to a share deal by convention.Regional context matters too. Compared with its ASEAN peers, Indonesia tends to be sector-specific on both approval timelines and ownership limits — a position eased somewhat since the Omnibus Law but still more fragmented than Singapore's faster, lighter-touch entry process. Award enforceability in Indonesian courts is also less predictable than in more arbitration-friendly jurisdictions, which is why cross-border agreements touching Indonesia default overwhelmingly to international arbitration — commonly under SIAC rules — rather than local court jurisdiction.Many investors continue to route Indonesian investments through a Singapore or Hong Kong holding structure, largely for tax treaty access and governance familiarity. Where this route is used, tax authorities increasingly expect genuine economic substance in the holding jurisdiction rather than a purely nominal presence — Singapore's substance requirements in particular have tightened, and treaty-shopping structures are drawing greater scrutiny across the region.3. Corporate Criminal Liability: The Single Biggest Shift for Deal DocumentsIf one development deserves the most attention from anyone structuring a deal with Indonesian exposure in 2026, it's Law No. 1 of 2026. The law formally codifies when a corporation — separate from its individual directors, commissioners, or employees — can face criminal prosecution, and aligns available sanctions with the new Criminal Code's penalty framework.Under the law, a corporation can be held criminally liable where an offense is committed by, for, or on behalf of the company by anyone exercising effective control, regardless of whether that person holds a formal position within the company. Individual directors and commissioners can be prosecuted alongside the corporate entity itself — meaning personal exposure for officers is no longer confined to regulatory or administrative penalties. Sentencing is aligned with the Criminal Code: where an offense would carry imprisonment for an individual, the corporate equivalent is a fine calculated at a prescribed multiple, alongside potential license revocation, confiscation of proceeds, and publication of the judgment.What this means for deal documents:Representations need to go further. Standard reps confirming no pending litigation are no longer sufficient. Buyers should require sellers to represent that neither the target nor its directors, commissioners, or key employees are subject to any criminal investigation, prosecution, or pending complaint, and to warrant that no conduct has occurred that would constitute a corporate offense under the new framework.Indemnities need a dedicated carve-out. Standard indemnities typically exclude criminal fines and penalties by default. Buyers should negotiate specific indemnification for losses arising from pre-closing corporate criminal conduct — potentially backed by a dedicated escrow tranche, since this exposure won't be picked up by general indemnity caps.D&O coverage needs confirmation, not assumption. Incoming directors should require written confirmation that D&O insurance is in place, that it has been checked against the new liability framework (at minimum for defense costs), and that run-off cover will continue for pre-closing conduct — typically for several years post-closing.MAC clauses should be updated. Material adverse change definitions should expressly capture the commencement of criminal proceedings under the new framework as a potential closing condition or walk-away trigger.Insurance buyers should also be aware of a coverage gap: most warranty and indemnity (W&I) policies exclude criminal fines and penalties, and standard fraud exclusions will typically also capture conduct that now qualifies as a corporate offense. In practice, this means W&I insurance — increasingly common in competitive Indonesian auction processes — should not be relied on as the primary protection against this category of risk. Escrow and holdback mechanisms remain the more dependable tool.4. Mandatory Compliance Assessments: A New Diligence BaselinePermenkum 49/2025 introduced a mandatory compliance self-assessment regime applying broadly to Indonesian limited liability companies, including PT PMA entities. Companies are expected to document their adherence to applicable law, their articles of association, internal policy, and good governance principles — and to maintain this as an ongoing program rather than a one-off exercise.For due diligence teams, this changes what a complete data room now looks like. Buyers should expect to request and review:Board and shareholder resolutions evidencing that key corporate actions were properly authorizedDocumentation of a designated compliance officer or functionInternal policies covering anti-bribery, anti-money laundering, data privacy, employment, and environmental matters, together with evidence of training and actual implementationWhistleblower reports, internal audit findings, remediation logs, and regulatory correspondenceThe annual compliance self-assessment report itselfA target that cannot produce a completed assessment should expect meaningfully more scrutiny — and sellers preparing for a sale process are well served by front-loading this work. A practical remediation sequence looks roughly like this: a gap analysis and compliance officer appointment in the first 30 days, drafted or updated internal policies with training rollout over the following month, and a completed self-assessment with documented remediation in the final stretch before the data room opens. Sellers who complete this work ahead of buyer due diligence tend to see fewer price adjustments and lighter escrow demands; those who cannot should expect the opposite.5. Pricing, Indemnity Design, and Escrow in a Higher-Risk EnvironmentThe cumulative effect of these reforms is that Indonesian deal structuring now runs through a materially higher-risk filter than it did two years ago. Where diligence surfaces compliance gaps, unresolved regulatory exposure, or potential criminal risk, buyers generally have three tools available, often used in combination:Purchase price adjustment — a downward adjustment reflecting quantified or estimated regulatory exposure, applied at closing or through a post-closing mechanism tied to a remediation schedule.Specific, uncapped or high-cap indemnities — targeted coverage for identified risks, particularly criminal and regulatory exposure. Sellers in Indonesian practice tend to resist uncapped indemnities, so this is increasingly a genuine point of negotiation rather than boilerplate.Deferred or contingent consideration — structuring part of the purchase price as deferred, with release conditions tied to the absence of criminal proceedings or regulatory sanctions within a defined post-closing window.On escrow specifically, a dedicated compliance escrow — commonly in the range of 5–15% of enterprise value, held for 24–36 months depending on risk profile — has become a more standard feature of Indonesian deal structures than it was previously, precisely because insurance coverage has real gaps in this area. Carving criminal and regulatory risk out of the general indemnity cap (so these claims sit outside standard thresholds) is another structuring choice worth building into term sheets early, rather than negotiating from a weaker position later in the process.6. Regulatory Approvals: Coordinating a More Complex SequenceIndonesian merger control remains a post-closing notification system administered by the Indonesia Competition Commission (KPPU) — but the practical challenge has never really been the KPPU filing in isolation. It's coordinating that filing with everything else that needs to happen around it.A transaction meeting the prescribed asset or revenue thresholds must be notified to the KPPU within 30 working days of the deal's legal effective date; a full substantive review, where triggered, can extend to 90 working days. In parallel, any transaction involving a change in foreign shareholding requires notification to BKPM, and — depending on the sector — separate clearance from bodies such as the Financial Services Authority (OJK) for financial institutions, the communications ministry for telecoms and digital businesses, or the energy ministry for mining and resources. Approval timeframes across these bodies vary widely, from roughly two to three weeks for standard BKPM notifications up to 60–90 days or more for licensed financial institution acquisitions.The practical risk isn't any single approval being denied — it's sequencing errors, where a deal closes without one of the required clearances in place, or where approvals are pursued in an order that creates avoidable delay. Mapping the full approval pathway before signing, not after, remains the difference between a clean close and a messy one.7. Due Diligence: What's New on the ChecklistBeyond the standard workstreams — corporate records, material contracts, employment, IP, insurance, and litigation — a handful of risk areas now warrant dedicated attention in any Indonesia-linked transaction:Compliance assessment status. Has the target completed a Permenkum 49/2025 self-assessment, and is a compliance officer formally appointed?Criminal exposure. Are there pending or historical criminal investigations involving the company or its directors? This requires a dedicated records search and regulatory correspondence review, not just a litigation disclosure schedule.Foreign ownership compliance. Does the target's actual business activity match its registered classification, and does foreign ownership sit within permitted caps?Tax and social security compliance. Are there unresolved tax disputes or gaps in mandatory social security (BPJS) contributions?Government and state-owned enterprise contract dependencies. Do key contracts include change-of-control consent or novation requirements that a transaction would trigger?Environmental permitting. Is the target's environmental impact assessment (AMDAL) documentation current and complete?Criminal and regulatory compliance diligence has effectively become a core workstream in Indonesian deals rather than a secondary check — a shift dealmakers should build into both timeline and budget from the outset of a transaction.8. Post-Closing: The First 90 Days Matter More Than They Used ToClosing a transaction in Indonesia is the beginning of the compliance workload, not the end of it. A well-run first 90 days typically includes:Data privacy alignment with Indonesia's Personal Data Protection Law, including updated data processing agreements, data subject notifications, and cross-border transfer assessments where relevant.Extension of anti-bribery and anti-corruption policies to the newly acquired entity, with prompt training for management and key commercial staff.Employment contract and benefits review, checking alignment with current labor regulations, including any changes to severance and termination provisions introduced by the Omnibus Law amendments.Regulatory filing updates, including BKPM registration changes, beneficial ownership filings, and sector-specific notifications reflecting the new ownership structure.9. Practical TakeawaysFor buyers, sellers, and general counsel currently evaluating or executing a transaction with Indonesian exposure, a few priorities stand out:Recheck sectoral ownership limits against the current framework before committing to a deal structure — don't rely on precedent from a prior transaction.Establish the target's compliance assessment status early. Gaps here will show up in pricing, indemnity, and escrow negotiations regardless of which side of the table you're on.Treat criminal risk diligence as its own workstream, not a subset of general litigation review.Update template transaction documents. Representations, indemnity caps, MAC definitions, and escrow mechanics built on pre-2026 precedent are no longer fit for purpose.Confirm — don't assume — D&O and W&I coverage adequacy, particularly around criminal liability exclusions.Map the full regulatory approval pathway before signing, coordinating BKPM, KPPU, and any sector regulators into a realistic transaction timetable.Indonesia's commercial appeal hasn't changed — scale, growth, and a deepening digital and consumer economy remain the draw. What has changed is the margin for structural error. Deals that are well-structured from the outset, with realistic diligence scope and deal documents built for the current regulatory environment, are the ones that close cleanly and stay closed.This article is intended for general informational purposes only and does not constitute legal or tax advice. Transaction structuring should be assessed against the specific facts, sector, and parties involved, in consultation with qualified legal and tax advisors.

Read Article →
Indonesia's Data Protection Landscape in 2026: The DPA Is Coming, Enforcement Is Real, and Cross-Border Transfers Are Shifting
Legal Update • Aug 11, 2026

Indonesia's Data Protection Landscape in 2026: The DPA Is Coming, Enforcement Is Real, and Cross-Border Transfers Are Shifting

For nearly four years, Indonesia's Personal Data Protection Law (Law No. 27 of 2022, "PDP Law") has operated without the one institution its own text says must exist: a dedicated supervisory authority. That gap is now closing, and it is closing at the same time as three other developments are converging — a landmark trade agreement with the United States, a growing body of court decisions applying the PDP Law's criminal and civil provisions, and the early shape of Indonesia's AI governance framework. Together, these developments mark a genuine inflection point for any organization — local or foreign — that processes the personal data of individuals in Indonesia.This update walks through what has changed, what is about to change, and what businesses should be doing about it now.1. The Data Protection Authority Is Finally Taking ShapeArticle 58(5) of the PDP Law required the government to establish a dedicated supervisory authority — commonly referred to as the Lembaga PDP or Data Protection Authority (DPA) — through a Presidential Regulation. For years, this remained a promise on paper. In the meantime, supervisory functions have been carried out on a transitional basis by the Ministry of Communication and Digital Affairs ("MOCD," also referred to as Komdigi), specifically through its Directorate General of Digital Space Supervision, under MOCD Regulation No. 1 of 2025 on its organization and work procedures.That transitional arrangement is now approaching its end. A draft Presidential Regulation establishing the DPA was made public at the end of February 2026, nearly four years after the PDP Law was enacted, and has been submitted to the Ministry of State Secretariat pending presidential approval.Key structural features of the draft regulation include:The DPA will be a non-ministerial government agency reporting to the President through the MOCD, though the MOCD will not exercise operational supervisory authority over it.The DPA will be led by a Head appointed by the President, supported by three deputies responsible for policy and guidance, dispute resolution, and compliance and enforcement respectively.Its mandate, set out in Articles 3 and 4 of the draft regulation, covers policy formulation, regulatory oversight, administrative enforcement, out-of-court dispute resolution, and any additional functions the President assigns.Transitional provisions are designed to make the DPA operational immediately upon establishment, initially drawing on the personnel and resources of MOCD's existing personal data protection unit, which will eventually be absorbed into the new agency.Separately, the implementing regulation for the PDP Law itself — the long-awaited Draft Government Regulation on PDP Law ("Draft GR PDP") — has also progressed. As of late 2025, the Draft GR PDP had completed its harmonisation process and been passed to the State Secretary for approval by the President, although no firm timeline for finalisation has been confirmed.Why this matters: once the DPA is operational, enforcement of the PDP Law shifts from an ad hoc, transitional posture to a dedicated regulator with the institutional mandate to investigate, sanction, and mediate disputes. Businesses that have treated PDP Law compliance as a lower-priority item pending a "real" regulator should expect that grace period to end.2. Cross-Border Data Transfers to the United States: A New WrinkleIndonesia's PDP Law has always taken a cautious approach to cross-border data transfers. Article 56 requires data controllers to ensure that the destination jurisdiction offers a level of personal data protection equivalent to or higher than Indonesia's own, generally to be confirmed through an adequacy-style assessment once implementing regulations are in place.The U.S.–Indonesia Agreement on Reciprocal Trade, dated 19 February 2026, complicates — and potentially reshapes — this picture. Under Article 3.2 of Annex III of the Trade Agreement, Indonesia committed to providing legal certainty for personal data transfers to the United States by recognizing the U.S. as a jurisdiction offering adequate data protection under Indonesian law. In practical terms, this suggests an intent to treat U.S. data protection standards as equivalent to Indonesia's own — a significant commitment given how differently the two jurisdictions have historically approached privacy regulation.However, two important qualifications apply:The Trade Agreement is not yet self-executing under Indonesian law. Under Article 84 of Law No. 7 of 2004 on Trade, the agreement must first be submitted to the House of Representatives (DPR) for a ratification process, which will determine whether approval is required and whether ratification proceeds through a Law or a Presidential Regulation.The PDP Law's own adequacy mechanism has not been bypassed. The obligation under Article 56 of the PDP Law is expected to be discharged through a formal adequacy assessment and decision by the DPA — an assessment that a trade instrument, on its own, cannot substitute for. It remains unclear how the government will operationalise the U.S. commitment: whether through a formal DPA adequacy determination, amendments to implementing regulations, a dedicated assessment process, or some other mechanism.Why this matters: organizations that route personal data to U.S.-based affiliates, vendors, or cloud infrastructure should not yet assume that transfers to the U.S. are automatically compliant. Standard contractual safeguards, consent-based transfer mechanisms, or reliance on existing tiered-transfer options under the PDP Law remain the safer near-term approach until the adequacy question is formally resolved.3. The Courts Are Applying the PDP Law — and the Numbers Are No Longer SmallA common assumption in the early years of the PDP Law was that enforcement would remain largely theoretical until a dedicated regulator existed. Court activity since 2022 suggests otherwise. Since the PDP Law took effect in October 2022, a review of publicly available court registries and government directories identified at least 23 criminal cases, 7 civil cases, and 6 constitutional court decisions involving the PDP Law, a figure likely understated given that not all cases are yet published.Criminal CasesThree notable criminal cases were decided by district courts in 2025, involving the misuse of identity information to create Telegram accounts and monetise one-time passwords, unauthorised access to government systems to extract and sell employee data on the dark web, and the misuse of personal data to unlawfully reactivate a dormant account. Courts found the defendants guilty under Article 65(3) of the PDP Law for unlawful use of personal data and Article 65(1) for unlawful data collection for personal gain.Two practical observations follow: the criminal provisions of the PDP Law are now fully operational in practice, confirming genuine criminal exposure for unlawful data collection and misuse, though courts have so far tended to rely primarily on the Electronic Information and Transactions Law (UU ITE) as the primary legal basis, with the PDP Law functioning as a secondary or alternative basis — a reflection of how enforcement practice is still maturing.Civil CasesA notable civil claim was filed before the West Jakarta District Court in January 2026 by three former contract employees against their employer, alleging unlawful processing of personal data, including credit-history checks conducted without consent or contractual basis, alongside various labour law claims. While the case remains pending, it illustrates that employee background and credit checks carried out without a proper privacy notice and lawful basis can expose employers to tort-based civil liability, separate from any contractual dispute. For HR and compliance teams, this is a timely reminder that PDP Law exposure is not limited to customer-facing data processing.Constitutional Court DecisionsThree constitutional challenges to the PDP Law were filed and rejected in 2025. The rulings are worth noting individually:Cross-border transfers (Article 56): the Constitutional Court held that adequacy assessments fall within the government's executive-administrative authority and that the PDP Law's tiered cross-border transfer framework is constitutionally sound.Criminal liability carve-outs (Articles 65(2) and 67(2)): the Court found that journalistic, academic, and artistic activities are already adequately protected through existing sectoral laws and PDP Law exemptions, making additional express carve-outs unnecessary.Consent formalities (Article 20(2)(a)): a challenge arguing that consent should only be valid via certified electronic signatures was rejected as legally unreasonable, with the Court noting that such technical requirements are properly addressed through implementing regulations rather than constitutional interpretation.Why this matters: the PDP Law's cross-border transfer framework is now constitutionally settled, making further judicial challenge on that front unlikely, while the criminal liability regime for unlawful disclosure remains intact and interpreted alongside sectoral laws rather than through new express exemptions.4. AI Governance Is Catching Up — FastIndonesia has so far governed AI-adjacent activity through a patchwork of instruments: the Electronic Information and Transactions Law, Government Regulation No. 71 of 2019 on electronic systems, and the PDP Law itself. That patchwork is starting to consolidate.A Presidential Regulation on AI Ethics and Safety is expected in 2026, having been pushed back from an original 2025 target, and was reported to be roughly 90% complete as of late 2025 according to local media. This regulation is expected to introduce mandatory requirements for high-risk AI systems, including registration and impact-assessment obligations — a structure conceptually similar to the risk-tiered approach seen under the EU AI Act, though scaled to Indonesia's regulatory context.At the same time, financial sector regulation is moving in parallel: OJK guidance applies data reliability standards directly to AI-driven credit scoring and risk assessment, given the severe consequences flawed outputs can have for individuals and systemic stability, and separately requires financial institutions to ensure AI does not inadvertently exclude underserved populations from access to financial services, alongside explicit expectations of compliance with the PDP Law and strong cyber resilience.On the intellectual property side, a Draft Copyright Bill is expected to address AI-generated works, with industry observers anticipating a distinction between works autonomously generated by AI — which may fall outside copyright protection — and works produced with substantial human creative direction. Platforms hosting AI-generated content should begin preparing for new licensing and liability obligations that may follow from this distinction.Why this matters: organizations deploying AI systems that process personal data — which, in practice, is most AI systems handling Indonesian user data — should treat the PDP Law and the forthcoming AI Ethics and Safety regulation as complementary compliance tracks, not separate ones. A system that is PDP Law–compliant today may still need to satisfy new registration or impact-assessment obligations once the AI regulation takes effect.5. What This Means in PracticeTaken together, these developments point toward a regulatory environment that is becoming more institutionalized, more actively enforced, and more entangled with Indonesia's broader trade and technology policy. Organizations operating in or dealing with Indonesia — including foreign SaaS providers, cloud platforms, and AI developers whose services reach Indonesian users under the PDP Law's extraterritorial scope — should prioritize the following:Track the DPA's establishment closely. Once operational, it will be the body issuing implementing regulations, setting administrative fine levels, and handling complaints and enforcement — details that will materially affect compliance planning.Reassess cross-border transfer mechanisms, especially U.S.-linked flows. Do not treat the Trade Agreement's adequacy language as a compliance shortcut until ratification and DPA-level implementation are clarified. Maintain contractual safeguards and documented lawful bases for transfers in the meantime.Audit internal HR data processing. The West Jakarta civil case is a reminder that background checks, credit checks, and other employee-related processing require the same lawful-basis and notice rigor as customer-facing data processing.Review the lawful basis for every processing activity, ensure each processing purpose is necessary and consistent with actual business operations, and train personnel involved in data handling — the same practical steps regulators and courts are increasingly scrutinizing.Get ahead of AI-specific obligations. Where AI systems process personal data or make consequential decisions (credit, employment, access to services), begin preparing documentation, impact assessments, and governance structures now, ahead of the AI Ethics and Safety regulation's entry into force.Closing ThoughtsIndonesia's data protection framework is moving out of its transitional phase. A dedicated regulator is close to becoming a reality, courts are actively applying criminal and civil provisions, the Constitutional Court has closed off several avenues for challenging the law's core structure, and AI-specific regulation is arriving on a parallel track. For businesses that have been waiting for a "real" enforcement environment before investing seriously in PDP Law compliance, that wait is ending.This article is intended for general informational purposes only and does not constitute legal advice. Organizations should seek specific guidance tailored to their data processing activities and corporate structure.Sources: developments described above draw on publicly reported regulatory and court filings as of Q1–Q2 2026, including client updates from regional law firms, government directories, and industry commentary on Indonesia's PDP Law, the U.S.–Indonesia Agreement on Reciprocal Trade, and Indonesia's forthcoming AI Ethics and Safety regulation.

Read Article →
Technology, Media & Telecommunications (TMT): A Roadmap for SaaS, Cloud Providers, Digital Platforms, and AI Developers Scaling Across Borders
TMT & Privacy • Aug 11, 2026

Technology, Media & Telecommunications (TMT): A Roadmap for SaaS, Cloud Providers, Digital Platforms, and AI Developers Scaling Across Borders

The Technology, Media & Telecommunications (TMT) sector has been one of the most dynamic engines of global economic growth over the past two decades. Unlike traditional manufacturing or retail industries, whose expansion is constrained by physical supply chains, TMT companies—particularly SaaS (Software-as-a-Service) providers, cloud providers, digital platforms, and AI developers—can reach users across multiple countries with a single "deploy." Yet this technical ease often masks a far more complex web of legal, regulatory, tax, and operational challenges than conventional businesses typically face.This article provides a comprehensive look at the TMT landscape for companies that are scaling—or planning to scale—across borders. It covers the core structural challenges, the key regulatory frameworks at play, practical risk-mitigation strategies, and emerging trends that industry players need to anticipate.1. Why TMT Is Different When It Comes to Global ExpansionSeveral unique characteristics make cross-border scaling in TMT require a distinct approach:a. Products are intangible and infinitely replicable Software code, AI models, and digital content require no warehouses or physical distribution. This accelerates time-to-market, but it also accelerates exposure to foreign regulation—sometimes before a company even realizes it has become legally "present" in a given jurisdiction.b. Data is both the core asset and the core risk For SaaS companies and digital platforms, user data is the fuel behind the business model—analytics, personalization, ad monetization, and training data for AI models. But that same data is also among the most heavily regulated assets in the world, from the EU's GDPR to California's CCPA/CPRA, to Indonesia's Personal Data Protection Law (UU PDP).c. Cloud infrastructure spans multiple jurisdictions Major cloud providers (hyperscalers) operate data centers across many countries, but decisions about where data is stored, processed, and replicated carry significant legal consequences—including data localization obligations that a growing number of developing countries now impose.d. Innovation outpaces regulation Generative AI is the clearest example: regulators in many countries are still drafting legal frameworks while AI products are already being used by millions of people. This creates legal uncertainty that companies must manage proactively rather than reactively.2. Key Challenges in Cross-Border Expansion2.1 Data Protection and Privacy ComplianceEvery jurisdiction takes a different approach to data protection:European Union (GDPR): requires a lawful basis for data processing, grants broad data subject rights, and mandates mechanisms for international data transfers such as Standard Contractual Clauses (SCCs).United States: a sectoral and state-by-state approach (CCPA/CPRA in California and various other state privacy laws), with no single unified federal law.Indonesia (Personal Data Protection Law No. 27/2022): requires explicit consent, mandates appointment of a data protection officer for certain categories of processing, and imposes cross-border transfer requirements that generally require the destination country to offer an equivalent level of protection or the existence of an applicable international agreement.China (PIPL): one of the strictest regimes globally, requiring a security assessment for cross-border data transfers above certain volume or category thresholds.For multi-tenant SaaS platforms and AI systems trained on user data, this challenge compounds further: data from a single enterprise customer in one country may end up being processed by infrastructure located in an entirely different country.2.2 Licensing, Permits, and Sector-Specific RegulationSeveral categories of digital services are subject to specialized licensing regimes:Fintech and digital payments: typically require licenses from local financial authorities (in Indonesia, for example, from the OJK or Bank Indonesia, depending on the type of service).Telecommunications and communication platforms: may be classified as electronic system operators subject to mandatory registration, such as the PSE registration requirement with Indonesia's Ministry of Communications and Digital Affairs for platforms serving Indonesian users.Media and content platforms: subject to content moderation rules, broadcasting rights, and in some cases local content quotas.2.3 Cross-Border Tax StructuringTax issues have grown increasingly complex with the emergence of concepts like Significant Economic Presence and Digital Services Taxes (DSTs), through which various countries seek to tax digital revenue even where a company has no physical permanent establishment there. The OECD's Pillar One and Pillar Two frameworks are also beginning to shape how multinational tech companies are subject to a global minimum tax. SaaS and cloud companies selling directly to consumers across borders need to understand cross-border VAT/GST obligations, such as the EU's One Stop Shop (OSS) regime or Indonesia's PMSE VAT collection obligation for foreign digital service providers.2.4 Intellectual Property and AI Model ProtectionAI developers face a distinct layer of IP risk:Ownership and originality of training data: potential copyright disputes over data used to train models, currently the subject of major litigation across multiple jurisdictions.Protection of models and algorithms: patent protection for AI methods is not uniformly recognized across countries; some jurisdictions apply stricter standards for the "inventive step" required for software and algorithms.AI-generated output: the question of who holds copyright over AI-generated content is still answered differently from country to country.2.5 Rapidly Evolving AI RegulationAI regulatory frameworks are evolving quickly and inconsistently:The EU AI Act applies a risk-based approach, imposing strict obligations on high-risk AI systems.Many Asian countries, including Indonesia, are currently developing AI ethics guidelines that are likely to evolve into more binding regulation over time.The United States has taken a more fragmented approach, with policy that can vary by state and remains subject to change depending on the direction of federal policy.This lack of uniformity forces AI companies to design flexible, jurisdiction-adaptable compliance frameworks rather than relying on a single generic approach across all markets.2.6 Employment and Entity StructuringExpanding teams across borders—whether through local entity formation, an Employer of Record (EOR) arrangement, or independent contractors—carries implications for income tax withholding, social security obligations, and the risk of an unintended "permanent establishment" (accidental PE), where the presence of employees in a country can be deemed to create corporate tax liability there even without a formal intent to establish a local entity.3. Considerations Specific to Each Business Model3.1 SaaS CompaniesContract structures (Master Service Agreements, Data Processing Agreements) must be adapted to the laws governing enterprise customers, particularly around liability caps, SLAs, and data breach notification clauses.Subscription-based pricing needs to account for currency fluctuations and cross-border VAT/GST obligations.Multi-tenant architecture requires contractual clarity on data residency for customers subject to data localization requirements.3.2 Cloud ProvidersData center placement decisions affect legal compliance as well as latency and user experience.Cloud providers often act as "data processors" for their customers, meaning their contractual and regulatory responsibilities differ from those of a "data controller."Cybersecurity obligations are tightening through frameworks such as the EU's NIS2 Directive and various sector-specific cybersecurity regulations across Asia.3.3 Digital Platforms (Marketplaces, Social Media, Content Platforms)Content moderation responsibilities are becoming increasingly regulated, including obligations to remove illegal content within specific time frames (following the trend set by frameworks such as the EU's Digital Services Act).Transparency requirements around recommendation algorithms are beginning to appear in various jurisdictions.Consumer protection in cross-platform transactions requires adaptation to local consumer protection laws.3.4 AI DevelopersThorough due diligence on training data sources is essential to minimize the risk of copyright disputes.Model documentation (model cards, risk cards) is increasingly becoming best practice and, in some jurisdictions, a regulatory expectation.Companies need mechanisms for human oversight of high-risk AI applications, particularly in healthcare, finance, and employment contexts.4. Risk Mitigation Strategies for TMT Companies Expanding GloballyMap regulations early. Conduct regulatory mapping for target markets before product launch—not after receiving a warning letter from a regulator.Privacy by design. Build product architecture that is flexible enough to accommodate different data protection regimes, including the ability to segment data by region.Adaptive corporate structuring. Consider holding companies, local subsidiaries, or strategic partnerships based on market needs, while carefully weighing the tax and legal liability implications of each.Strong, scalable contracts. Standardize core contract templates, but build in adaptable addendum modules that can be tailored to local law without restructuring the entire agreement.Cross-functional collaboration. Involve legal, tax, cybersecurity, and product teams from the earliest stages of expansion planning—not only once problems arise.Continuous regulatory monitoring. Given the pace of change in TMT regulation—especially around AI—companies need an ongoing regulatory monitoring mechanism, whether through an internal team or external advisors.Vendor and partner due diligence. Ensure data sub-processors, infrastructure providers, and local distribution partners meet the same compliance standards the company applies internally.5. Trends to WatchConvergence of AI and data regulation, as AI governance rules become increasingly integrated with existing data protection frameworks.Rising data localization requirements in developing markets, including Indonesia, as part of broader data sovereignty policies.Increasingly coordinated global digital taxation through the OECD framework, even as implementation continues to vary from country to country.Growing emphasis on interoperability and data portability standards, pushing platforms toward more open system design.Intensifying scrutiny of generative AI models, particularly around training data transparency and output bias.6. ConclusionCross-border expansion offers enormous growth potential for SaaS providers, cloud providers, digital platforms, and AI developers—but it also comes with a regulatory landscape that is constantly shifting and far from uniform across markets. Success at global scale depends not only on the strength of the product and technology, but on a company's ability to build a solid foundation of legal compliance, data governance, tax structuring, and AI governance from the earliest stages of growth.Companies that treat cross-border compliance as an integral part of their product strategy—rather than a mere administrative obligation—will hold a lasting competitive advantage: they can move faster into new markets, build trust with enterprise customers, and reduce the risk of operational disruption from regulatory disputes down the line.Note: This article is intended for general informational purposes, offering a broad overview of the TMT landscape in the context of cross-border expansion. For guidance specific to a particular business situation, consult legal and tax advisors familiar with the relevant jurisdictions.

Read Article →
Stay Informed

Receive Legal & Market Updates

Subscribe to our brief, practical updates on changes in Indonesian regulation, cross-border compliance, and commercial law.

We respect your inbox. No spam, only critical updates.