Indonesia - Electronic Transactions Law (1/2024)
Law of the Republic of Indonesia Number 1 of 2024 on the Second Amendment to Law Number 11 of 2008 on Electronic Information and Transactions
Undang-Undang Republik Indonesia Nomor 1 Tahun 2024 tentang Perubahan Kedua atas Undang-Undang Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik
Indonesia
RAI-ID-NA-URIN1XX-2024UU No. 1/2024 is the second amendment to the original 2008 Electronic Information and Transactions Law (UU ITE). It clarifies and adds targeted provisions on electronic certification services, obligations for electronic system operators (Penyelenggara Sistem Elektronik, PSE) including child protection measures, and administrative sanctions for non-compliance while retaining core provisions for electronic information, transactions, and criminal liability subject to constitutional review.
Summary
Undang-Undang Republik Indonesia Nomor 1 Tahun 2024 (UU No. 1/2024) is the statutory second amendment to the founding Electronic Information and Transactions Law (UU No. 11/2008) as previously amended by UU No. 19/2016. Promulgated and entered into force on 2 January 2024, the Act introduces a set of targeted changes and seven new articles (including Articles 13A, 16A, 16B, 18A, 27A, 27B, and 40A) designed to reduce ambiguity in application, strengthen legal certainty in the digital domain, and address specific regulatory gaps identified in practice. Major areas of amendment include: (1) formal recognition and scope for Electronic Certification Service Providers (Penyelenggara Sertifikasi Elektronik) — enumerating services such as electronic signatures, electronic seals, time-stamping, registered electronic delivery, website authentication, preservation of electronic signatures/seals, digital identity, and other certificate-based services; (2) new obligations for Penyelenggara Sistem Elektronik (PSE) to implement protective measures for children using or accessing electronic systems — including minimum age information, child-user verification mechanisms, and abuse-reporting channels; (3) a clearer administrative enforcement regime against PSEs that fail to meet statutory obligations, with specified administrative remedies such as written warnings, administrative fines, temporary suspension, and termination of access; and (4) clarifying language on certain offenses and scope of liability. The Act retains criminal provisions related to misuse of electronic information and transactions but was subject to constitutional review. In April 2025 the Constitutional Court (Mahkamah Konstitusi) issued decisions that narrowed the application of several provisions of UU No. 1/2024 — notably excluding digital “kerusuhan” (disorder/commotion in digital space) from punishable conduct under certain articles and limiting defamation-type enforcement to natural persons rather than institutions (see Putusan MK Nomor 115/PUU-XXII/2024 and 105/PUU-XXII/2024, 29 April 2025). The Act is operationalized through implementing regulations and sectoral guidance from the Ministry of Communication and Informatics (Kementerian Komunikasi dan Informatika, KOMINFO) and other agencies. Practically, UU No. 1/2024 modernizes legal recognition for electronic trust services, raises platform-level child protection expectations, and creates a mixed administrative-criminal enforcement model that continues to evolve via implementing rules and judicial clarifications. Organizations and service providers operating electronic systems in or directed at Indonesia should review their systems for electronic certification practices, child protection features, reporting/response workflows, and compliance with registration/notification obligations under the Act and subsequent KOMINFO rules.
Full article
Read full text ↗Overview
The Second Amendment (Undang-Undang Nomor 1 Tahun 2024) updates the Indonesian Electronic Information and Transactions framework to improve legal clarity and operational governance in digital spaces. Enacted on 2 January 2024, the amendment adds seven new articles and expressly recognizes a set of electronic certification services (electronic signatures, seals, time stamps, authenticated delivery, website authentication, preservation, and digital identity). It also imposes specific child protection duties on Penyelenggara Sistem Elektronik (PSE). The law establishes administrative sanctions for PSE non-compliance (written warnings, administrative fines, temporary suspension, and discontinuation of access) and retains criminal liability provisions subject to later constitutional interpretation. Official text and explanatory notes are published on government legal information portals, for example the Ministry JDIH and the national legal repository. See the official registry at JDIH Ministry of Communication and Informatics and the national regulation database at Peraturan BPK (Regulatory Database).
Definitions
The Act preserves core definitions from the 2008 law ("Electronic Information", "Electronic Documents", "Electronic Systems", "Electronic Signatures", "Penyelenggara Sistem Elektronik/PSE") and adds defined scope around "Penyelenggara Sertifikasi Elektronik" (Electronic Certification Service Providers) and child-protection related terms (e.g., "child user", "minimum age"). The new Article 13A enumerates certificate-based services (electronic signature, electronic seal, time-stamping, registered electronic delivery, website authentication, preservation of signatures/seals, digital identity services, and other certificate services). Definitions remain primarily functional rather than highly technical to preserve legal adaptability to technology changes.
Governance and Institutional Framework
Regulatory oversight and operational governance remain centered on the Ministry of Communication and Informatics (Kementerian Komunikasi dan Informatika). The Act delegates implementation detail and administrative enforcement to the Government and Ministerial regulations; implementing measures and registration frameworks are expected from KOMINFO and related agencies. The law indicates publication in the State Gazette (Lembaran Negara) and places implementing guidance on official JDIH nodes such as the Secretariat-General of the DPR and KOMINFO’s JDIH. See the DPR and KOMINFO registry entries: DPR JDIH listing and Kominfo JDIH page. The Constitutional Court (Mahkamah Konstitusi) sits as the final interpreter of constitutionality and has issued decisions refining the Act’s application; see MK press release 29 April 2025. Inter-agency coordination (Justice, Law Enforcement, Children’s Welfare agencies, and sectoral regulators for finance and health) is expected for cross-cutting enforcement.
Key Focus Areas
The amendment targets several interlocking policy priorities: clarifying electronic trust services; strengthening protections for children online; refining liability and delictal scope for reputational harm and content that disturbs public order; and creating a proportional administrative enforcement ladder against PSEs. The Act responds to practical issues observed under the 2008/2016 texts where terms and enforcement led to legal uncertainty. For electronic trust, Article 13A lists services under certification providers and opens a legal basis for recognized electronic signatures and digital identity frameworks (a necessary step for e-government, e-commerce, and cross-border digital transactions). For children, Articles 16A–16B require PSEs to provide minimum-age information, verification mechanisms, and abuse reporting channels — measures intended to reduce exposure and harm. The Act’s enforcement architecture prioritizes administrative sanctions against PSEs while preserving criminal sanctions for certain intentional offenses, though the Constitutional Court later narrowed some applications of those criminal provisions (see Putusan MK Nomor 105/PUU-XXII/2024 and 115/PUU-XXII/2024 on 29 April 2025). The law also contemplates preservation, time-stamping, and authenticated delivery services to support evidentiary certainty in electronic transactions.
Implementation Framework
Implementation depends on follow-on Government and Ministerial regulations that detail registration/notification requirements, technical standards for certification services, child-protection implementation guidelines, reporting formats, and administrative sanction procedures. The Act itself sets the policy and legal baseline; operationalization includes (a) registration/recognition of Electronic Certification Service Providers, (b) KOMINFO-issued rules for PSE obligations and complaint processes, (c) sector-specific interoperability and data handling rules (e.g., finance and health), and (d) enforcement protocols for issuing written warnings, levying administrative fines, ordering temporary suspensions, or directing termination of access. Developers and PSE operators should monitor KOMINFO JDIH entries and Peraturan Pemerintah/Peraturan Menteri that implement the Act (see Kominfo 2024 inventory).
Monitoring and Evaluation
The Act establishes a statutory basis for administrative oversight and requires ministry-level monitoring of compliance. Metrics for evaluation will include the number of registered electronic certification providers, PSE compliance rates with child-protection measures, number and type of administrative sanctions issued, and trend data on ITE-related complaints. The implementing regulations are expected to specify reporting frequency, data to be collected, and indicators for performance. The DPR and sectoral oversight bodies may require periodic reporting on the law’s implementation and impacts on free expression, child safety, and market activity.
Penalties, Liability, and Appeals
UU No. 1/2024 sets administrative sanctions specifically targeted at PSE non-compliance (written warnings, administrative fines, temporary suspension, and termination of access) and preserves criminal liability for certain offenses originating from the 2008/2016 framework. However, the Constitutional Court’s April 29, 2025 decisions narrowed certain wordings: it limited the criminalization of digital "kerusuhan" (commotion) and restricted defamation-type applications so only natural persons (not institutions or organizations) may be complainants in certain offenses. Appeals from administrative sanctions follow the administrative/administrative-judicial procedures outlined by implementing regulations and general administrative law. Criminal prosecutions remain subject to ordinary criminal procedure and constitutional case law emerging from MK rulings (see Peraturan BPK summary and MK press release).
Relationship to Other Instruments
UU No. 1/2024 amends and sits alongside Undang-Undang Nomor 11 Tahun 2008 (original ITE) and Undang-Undang Nomor 19 Tahun 2016 (first amendment). It interacts with: electronic signature regulations, sectoral data protection rules, child-protection statutes, criminal law (KUHP), and government/ministerial regulations that establish technical and operational standards. Subsequent Peraturan Pemerintah (Government Regulations) and Peraturan Menteri (Ministerial Regulations) are expected to implement specific obligations introduced by the Act. Official databases that index the relationship include the DPR and KOMINFO JDIH repositories and the national law register at Peraturan BPK (DPR JDIH and Peraturan BPK).
International Alignment
The Act’s recognition of electronic certification services and digital identity aligns Indonesia’s legal framework with international norms on electronic trust services and e-signatures (comparable in intent to UNCITRAL e-commerce principles and many national e-signature laws), while child-protection obligations reflect global policy trends for platform responsibility. Cross-border interoperability, mutual recognition of electronic signatures, and data transfer considerations will depend on future implementing rules and international agreements. Stakeholders engaged in cross-border services should monitor KOMINFO guidance and bilateral frameworks for digital certificates and identity recognition.
Implementation Timeline
| Milestone | Target/Date |
|---|---|
| Act promulgated and in force | 2024-01-02 |
| Publication in State Gazette (Lembaran Negara) | 2024 (LN No. 1 / TLN 6905) |
| Constitutional Court rulings narrowing some provisions | 2025-04-29 |
| Expected KOMINFO implementing regulations (registrations/standards) | Issued progressively after 2024 (monitor JDIH KOMINFO) |
Sources and References
| Source | Type |
|---|---|
| Undang-Undang Nomor 1 Tahun 2024 (Kominfo JDIH) | Primary Source |
| Undang-Undang Nomor 1 Tahun 2024 (Peraturan BPK) | Primary Source |
| DPR JDIH – UU List 2024 | Primary Source |
| Mahkamah Konstitusi press release (29 April 2025) | Primary Source |
Requirements for a company
What an organisation has to do under Indonesia - Electronic Transactions Law (1/2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
7- Provide clear minimum-age information to child users of electronic systems.Electronic System Operators (PSE)
- Establish and maintain accessible channels for reporting abuse concerning child users.Electronic System Operators (PSE)
- Comply with administrative sanctions, including warnings, fines, suspensions, or access termination.Electronic System Operators (PSE)
- Register or notify the authorities as an Electronic Certification Service Provider.Electronic Certification Service Providers
- Implement mechanisms to verify the age of child users where required.Electronic System Operators (PSE)
- Implement technical standards for electronic certification services as detailed in implementing regulations.Electronic Certification Service Providers
- +1 more in the table below
Must not do
0Nothing in this category.
Should do
2- Monitor KOMINFO JDIH entries for new implementing regulations and guidelines.Developers and Electronic System Operators (PSE)
- Adopt retention and preservation policies for electronic documents and signatures to ensure evidentiary certainty.Entities handling electronic documents and transactions
Should not do
0Nothing in this category.
Who must do what
The obligations under Indonesia - Electronic Transactions Law (1/2024), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Electronic System Operators (PSE) | Provide clear minimum-age information to child users of electronic systems. “Articles 16A–16B require PSEs to provide minimum-age information” | Jan 2, 2024 | Articles 16A–16B | Critical |
| 2 | Electronic System Operators (PSE) | Establish and maintain accessible channels for reporting abuse concerning child users. “Articles 16A–16B require PSEs to provide... abuse reporting channels” | Jan 2, 2024 | Articles 16A–16B | Critical |
| 3 | Electronic System Operators (PSE) | Comply with administrative sanctions, including warnings, fines, suspensions, or access termination. “The law establishes administrative sanctions for PSE non-compliance (written warnings, administrative fines, temporary suspension, and discontinuation of access)” | As specified in sanction order | — | Critical |
| 4 | Electronic Certification Service Providers | Register or notify the authorities as an Electronic Certification Service Provider. “operationalization includes (a) registration/recognition of Electronic Certification Service Providers” | Monitor KOMINFO for specific deadlines | — | Important |
| 5 | Electronic System Operators (PSE) | Implement mechanisms to verify the age of child users where required. “Articles 16A–16B require PSEs to provide... verification mechanisms” | Monitor KOMINFO for specific guidelines | Articles 16A–16B | Important |
| 6 | Electronic Certification Service Providers | Implement technical standards for electronic certification services as detailed in implementing regulations. “Implementation depends on follow-on Government and Ministerial regulations that detail... technical standards for certification services” | Monitor KOMINFO for specific deadlines | — | Important |
| 7 | Electronic Certification Service Providers | Offer certificate-based services such as electronic signatures, seals, time-stamping, or digital identity. “Article 13A enumerates certificate-based services (electronic signature, electronic seal, time-stamping, registered electronic delivery, website authentication, preservation of signatures/seals, digital identity services, and other certificate services).” | — | Article 13A | Important |
| 8 | Developers and Electronic System Operators (PSE) | Monitor KOMINFO JDIH entries for new implementing regulations and guidelines. “Developers and PSE operators should monitor KOMINFO JDIH entries and Peraturan Pemerintah/Peraturan Menteri that implement the Act” | Ongoing | — | Recommended |
| 9 | Entities handling electronic documents and transactions | Adopt retention and preservation policies for electronic documents and signatures to ensure evidentiary certainty. “The law also contemplates preservation, time-stamping, and authenticated delivery services to support evidentiary certainty in electronic transactions.” | — | — | Recommended |
Related Regulations
Peraturan Pemerintah Republik Indonesia Nomor 71 Tahun 2019 tentang Penyelenggaraan Sistem dan Transaksi Elektronik (Government Regulation No.71/2019 on Electronic Systems and Transactions)
Indonesia91% similar
Undang-Undang Republik Indonesia Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (Law No.27/2022 on Personal Data Protection)
Indonesia89% similar
Rancangan Undang-Undang tentang Kecerdasan Buatan (Draft Bill on Artificial Intelligence)
Indonesia88% similar
Rancangan Peraturan Presiden tentang Kecerdasan Buatan (Draft Presidential Regulation on Artificial Intelligence)
Indonesia86% similar
Konsep Pedoman Etika Kecerdasan Artifisial (Concept Draft of Ethical Guidelines for AI)
Indonesia86% similar
© Regulations.AI · updated on 13-Jun-2026