← Back to list

Limits, Threats, and Protections: How Indonesian Cyber ​​Law Regulates Our Digital Activities

In an era where nearly all of our activities are connected to the internet, understanding cybersecurity is no longer just a secondary skill…

Lutsvia · 2025-12-11 05:23 · 0 claps · 3.2 min read
#uu-ite #cybersecurity #learning #ojk #uu-pdp
Open on Medium ↗
Wiki topics: EDU · Education & Learning 🔒 · Cybersecurity ⚖️ · Law & Justice

Limits, Threats, and Protections: How Indonesian Cyber ​​Law Regulates Our Digital Activities

In an era where nearly all of our activities are connected to the internet, understanding cybersecurity is no longer just a secondary skill — it’s a fundamental necessity. Many people, including IT students and technology users in general, often assume that cyberspace is solely about technical matters like networking, coding, malware, or hacking. However, one crucial aspect that is often overlooked is the legal framework governing digital behavior in Indonesia. Regulations such as the ITE Law, the Criminal Code, the Personal Data Protection Law (PDP Law), as well as regulations from the Financial Services Authority (OJK) and Bank Indonesia, all serve to keep the digital space safe, orderly, and fair for everyone.

Interestingly, these laws can be three things at once: a restriction for those who want to learn or experiment with technology, a threat to those who dare to violate or act without permission, and protection for anyone who becomes a victim of digital crime.

What is the ITE Law? (Law №11/2008 — Amendments 2016 & 2024)

The ITE Law regulates:

  • Electronic Information & Electronic Transactions
  • Illegal Access (Hacking)
  • Hacking, Data Theft, and the Distribution of Malware
  • Dissemination of Hoaxes/Hate Speech
  • Electronic Evidence in Legal Proceedings

In essence: The ITE Law regulates digital behavior, so that cyberspace in Indonesia remains safe, clean, and orderly.

What is the Criminal Code related to Cybercrime?

The Criminal Code (KUHP) contains articles for:

  • Unauthorized access (similar to “breaking into” a system)
  • Illegal wiretapping
  • Destruction, removal, or alteration of electronic data
  • Online fraud

The Criminal Code serves as a general criminal basis, while the ITE Law is more specific regarding cybercrime.

ITE Law and Criminal Code for Students: Boundary, Threat, Protection

1) Boundary

This law serves as a safeguard. IT or cybersecurity students should be aware that activities such as:

  • Unauthorized port scanning
  • Attempting to access campus systems
  • Duplicating databases
  • Unauthorized vulnerability testing is illegal, even for “learning purposes.”

2) Threat

Violations can result in:

  • a fine of hundreds of millions of rupiah
  • 6–10 years in prison for certain cases
  • administrative sanctions from the institution

Example: brute-force login to campus Wi-Fi = illegal access.

3) Protection

If you become a victim, the same laws protect you:

  • digital defamation
  • doxing
  • dissemination of private photos
  • account hacking
  • online fraud

PDP Law (Law №27/2022 — Personal Data Protection)

The PDP Law is the “Indonesian version of GDPR.” It stipulates that:

  • Personal data may not be processed without consent
  • Data owners have the right to know what their data is being used for
  • Organizations are required to protect data properly
  • Data breaches must be reported + subject to criminal and administrative sanctions

Examples of personal data: National ID Number (NIK), National ID Card (KTP), email, IP address, location, photo, transaction history.

PP 71/2019 (PSTE — Implementation of Electronic Systems and Transactions)

Regulates:

  • Obligations of Electronic System Providers (PSE) Examples: marketplaces, health apps, fintech, universities, government agencies
  • Data storage locations (data centers & data disaster recovery)
  • Minimum security standards
  • Obligation to report cyber incidents

This PP is important for digital companies.

Financial Regulation: OJK & Bank Indonesia

Financial sector = the most stringent sector.

OJK

Regulates:

  • IT risk management
  • security audits
  • digital consumer protection
  • cyber incident mitigation obligations for fintech, banks, and insurance companies

Bank Indonesia

Regulates:

  • Payment transaction security
  • Security standards for QRIS, mobile banking, and e-wallets
  • National payment infrastructure security

International Standard: ISO/IEC 27001

Not a law, but a global standard for:

  • Information Security Management System (ISMS)
  • Security risk management
  • Securing information assets
  • Technical and administrative controls

Large companies often use this standard as a requirement for trust and audits.

Real Case Examples of Cybercrime (due to ignorance/negligence)

1) School/Campus Website Hacking Case

Students attempted a “trial hack” into campus servers without permission → arrested for illegal access despite their intent to study.

Impact: – Server down, grade data inaccessible – Campus reputation compromised – Students charged under the ITE Law

2) Spam & Phishing Cases for “Fun”

Someone sends a fake link to “prank a friend” → The friend loses account access, and their personal data is leaked.

Impact: – The victim becomes the target of fraud – The perpetrator is threatened with charges of fraud and illegal access

3) Attendance System Manipulation Case

A student altered attendance data by infiltrating the lab database.

Impact: – System corruption – Data integrity loss – Perpetrator faces charges of manipulating electronic information

These laws exist to keep the digital space safe, ensure all activities are conducted ethically, and protect the public from harm. Therefore, learning cybersecurity isn’t just about understanding the technical aspects; understanding the legal aspects is equally important, ensuring that learning, experimentation, and research remain safe and responsible.

THANKS AND SEE YOU!!


메타데이터
post_id
b5eed56e6a0a
slug
limits-threats-and-protections-how-indonesian-cyber-law-regulates-our-digital-activities-b5eed56e6a0a
url
https://medium.com/@28411011/limits-threats-and-protections-how-indonesian-cyber-law-regulates-our-digital-activities-b5eed56e6a0a
canonical_url
https://medium.com/@28411011/limits-threats-and-protections-how-indonesian-cyber-law-regulates-our-digital-activities-b5eed56e6a0a
author_url
https://medium.com/@28411011
status
ok
fetched_at
2026-07-15 08:17:25