Blog post
January 6, 2026

Indonesia’s PDP law and social listening: what buyers need to know in 2026

Indonesia’s Personal Data Protection Law (Law No. 27/2022) finished its two-year transition period in October 2024. Every organisation that processes personal data in Indonesia is now expected to comply. Yet the landscape remains unusually uncertain: the supervisory PDP Agency has not been established, the implementing regulation is still undergoing harmonisation, and a January 2026 omnibus law on criminal provisions (Law No. 1/2026) revised penalty clauses across multiple statutes, including the PDP Law. For social listening buyers, this creates a compliance environment where the obligations are clear but the enforcement infrastructure — and some of the finer regulatory detail — is still taking shape.

What the PDP law requires

The PDP Law establishes comprehensive data protection requirements modelled on GDPR principles but adapted for Indonesia’s context. Key provisions affecting social listening include purpose limitation (data can only be processed for stated purposes), storage limitation (data cannot be retained beyond the period necessary), data subject rights (including access, correction, and deletion), cross-border transfer requirements, and data breach notification.

The consent framework is thorough. Data controllers must provide clear information about the purpose of processing, the type of personal data collected, and the retention period before obtaining consent. For social listening, this means organisations cannot simply begin monitoring Indonesian social media without establishing a documented legal basis.

A notable feature of the PDP Law is that it does not appear to provide an explicit exemption for publicly available data — a distinction from Singapore’s PDPA, which does include such a carve-out. Many legal commentators have interpreted this to mean that even public posts on platforms like Facebook, TikTok, and X are considered personal data when they can be linked to identifiable individuals, bringing aggregation, analysis, and storage of such data under PDP Law obligations. However, the implementing regulation has not been finalised, and no supervisory authority exists yet to issue authoritative guidance on this point. Organisations should work with local legal counsel to assess how this provision applies to their specific social listening activities, as the regulatory position may become clearer once the PDP Agency is operational.

The absence of the supervisory agency creates practical uncertainty more broadly. Organisations are expected to comply with the law’s requirements, but there is no regulatory body to issue guidance, respond to queries, or enforce compliance. This vacuum has led many organisations to adopt a wait-and-see posture — a strategy that carries real risk when the agency becomes operational and begins reviewing existing data processing practices.

The enforcement horizon

The PDP Agency is expected to become operational in 2026–2027. The draft Presidential Regulation establishing the Agency has gone through multiple harmonisation rounds. Legal experts anticipate the Agency will prioritise establishing its organisational structure, issuing implementing guidelines, and building enforcement capacity before pursuing widespread enforcement actions.

When enforcement begins, the Agency will likely focus initially on high-profile cases involving large-scale data processing, cross-border transfers, and sector-specific complaints. Social listening — which involves processing volumes of personal data from public and semi-public sources — is the type of activity that could attract regulatory attention.

It is worth understanding the penalty structure clearly. The PDP Law sets criminal fines for individuals at up to IDR 4–6 billion depending on the offence, with corporate penalties multiplied by up to ten times the individual amount. The highest corporate criminal fine — IDR 60 billion (approximately USD 3.68 million) — applies specifically to the offence of creating false or fake personal data. Other violations carry lower but still substantial corporate maximums: up to IDR 50 billion for unlawful collection or use of personal data, and up to IDR 40 billion for unlawful disclosure. Administrative fines of up to 2% of annual revenue apply separately. Beyond monetary penalties, courts can order confiscation of profits, suspension of business operations, licence revocation, or even corporate dissolution.

Separately, Law No. 1/2026 — an omnibus law on criminal provisions dated 2 January 2026 — adjusted criminal sanction clauses across several Indonesian statutes, including the PDP Law. This is part of a broader legislative programme on criminal law reform rather than a targeted amendment to data protection specifically, but it reflects ongoing legislative attention to the penalties framework.

For social listening buyers, the compliance imperative is clear: build governance frameworks now, while there is time to implement them properly, rather than scrambling to comply once enforcement begins.

Practical compliance steps for social listening

The compliance approach should address four areas specific to social listening operations. The guidance below reflects Isentia’s interpretation of the current regulatory landscape and should not be treated as legal advice. We strongly recommend engaging qualified Indonesian legal counsel to develop a compliance strategy tailored to your organisation.

  • Document your lawful basis for processing: Given the apparent absence of a publicly available data exemption, many legal practitioners point to legitimate interest as a potentially viable basis — that the organisational benefit of social listening outweighs the potential adverse effect on data subjects. This would require a documented legitimate interest assessment for each monitoring programme. However, as the PDP Agency has not yet issued guidance on how lawful bases should be applied in practice, this approach should be validated with local counsel and revisited as regulatory guidance emerges.
  • Implement retention policies: Social listening platforms that store historical data indefinitely create compliance risk. Define retention periods based on actual analytical needs and configure your platform to enforce them.
  • Establish access controls: Restrict access to social listening data to personnel who have a documented need. Maintain audit trails for data access and use.
  • Prepare for cross-border transfers: If your social listening vendor stores or processes data outside Indonesia, document the transfer arrangements and ensure adequate protection in recipient jurisdictions.

How Isentia supports PDP law readiness

Pulsar Group — Isentia’s parent company — holds ISO/IEC 27001:2022 certification for information security management and ISO 9001 certification for quality management, covering its portfolio of brands including Isentia. These independently audited certifications provide a compliance foundation for buyers who need to demonstrate that their vendors meet recognised international standards for data security and operational quality.

The Pulsar platform offers configurable retention periods, role-based access controls, and audit trails that support the kind of documentation the PDP Law requires. While no platform can guarantee regulatory compliance on its own — compliance is ultimately an organisational responsibility — these capabilities give social listening buyers the technical controls needed to implement a defensible governance framework.

Frequently asked questions

Does Indonesia’s PDP Law exempt publicly available social media data?

The PDP Law does not contain an explicit exemption for publicly available data, unlike Singapore’s PDPA. Most legal commentators interpret this to mean that public social media posts linked to identifiable individuals are considered personal data. The implementing regulation and future PDP Agency guidance may provide further clarity.

When will the PDP Agency begin enforcement?

The PDP Agency is expected to become operational in 2026–2027. The implementing regulation is undergoing harmonisation, and the Agency will need to establish its structure and issue guidelines before widespread enforcement begins.

What are the maximum penalties under the PDP Law?

Corporate criminal fines range from IDR 40 billion to IDR 60 billion depending on the offence, with the highest figure applying to the creation of false personal data. Administrative fines of up to 2% of annual revenue apply separately. Additional sanctions can include asset confiscation, business suspension, and corporate dissolution.


*Disclaimer: This blog is for informational purposes only and does not constitute legal advice. Indonesia’s PDP Law regulatory environment is evolving, and organisations should consult qualified Indonesian legal counsel for guidance specific to their circumstances.

Learn more


If you’re interested in how Isentia can support your brand and strategy, simply fill out the form below and one of our specialists will contact you!


Share

Similar articles

object(WP_Post)#7692 (24) { ["ID"]=> int(49595) ["post_author"]=> string(2) "75" ["post_date"]=> string(19) "2026-08-26 03:39:30" ["post_date_gmt"]=> string(19) "2026-08-26 03:39:30" ["post_content"]=> string(3210) "

Would you trust a brand more if an AI model recommended it? For many, the answer is yes – and it’s changing the very nature of PR & Comms.

Our latest report digs into the changing nature of trust, as audiences turn to AI models for quick answers instead of going to organisations or media outlets directly, with AI fast becoming the final stop in the comms cycle. 

This report unpacks:

  • Why trust has shifted, and where audiences are having these conversations
  • Why AI has become the last stop in the comms cycle
  • Methods for staying on top of your brand trust and reputation

To access the full report, fill in the form below:

Discover our Lumina AI suite here.


" ["post_title"]=> string(63) "How AI is destabilising trust and reputation amongst audiences?" ["post_excerpt"]=> string(144) "Learn how LLMs reshape brand perception and actionable steps organisations can take to maintain trust and reputation in the new information era." ["post_status"]=> string(7) "publish" ["comment_status"]=> string(4) "open" ["ping_status"]=> string(4) "open" ["post_password"]=> string(0) "" ["post_name"]=> string(62) "how-ai-is-destabilising-trust-and-reputation-amongst-audiences" ["to_ping"]=> string(0) "" ["pinged"]=> string(0) "" ["post_modified"]=> string(19) "2026-08-26 03:46:01" ["post_modified_gmt"]=> string(19) "2026-08-26 03:46:01" ["post_content_filtered"]=> string(0) "" ["post_parent"]=> int(0) ["guid"]=> string(32) "https://www.isentia.com/?p=49595" ["menu_order"]=> int(0) ["post_type"]=> string(4) "post" ["post_mime_type"]=> string(0) "" ["comment_count"]=> string(1) "0" ["filter"]=> string(3) "raw" }
Blog
How AI is destabilising trust and reputation amongst audiences?

Learn how LLMs reshape brand perception and actionable steps organisations can take to maintain trust and reputation in the new information era.

object(WP_Post)#8981 (24) { ["ID"]=> int(49408) ["post_author"]=> string(2) "75" ["post_date"]=> string(19) "2026-08-20 02:44:11" ["post_date_gmt"]=> string(19) "2026-08-20 02:44:11" ["post_content"]=> string(16590) "

If you ask ChatGPT or Gemini about your organisation today, the answer won't come straight from your website. Instead, it uses sources the model already trusts, which are often months or years old. So if your last big mention was a crisis or a controversy from 2023, that's probably still how AI describes you.

This is the tough reality for anyone working in PR and communications today. More people are getting their first—and sometimes only—impression of your organisation from an AI-generated summary, not from search results or the homepage. And these summaries often rely on outdated information.

What does freshness actually mean?

Content freshness refers to how recent the sources are that an AI model uses when it talks about you. It might seem like a minor technical point, but it's actually very important.

Search engines have always valued fresh content, and they let you update information quickly. If you change a page, Google recrawls it, and rankings can shift in days. Large language models don't work like this. As Lisa Main, Director at Main Bureau, said on Isentia's "AI as a Stakeholder" panel,  "large language models are not databases of verified facts." These models are trained on a snapshot of the internet, updated only from time to time, and they rely on sources that were already prominent when they were trained. This means a past crisis or a controversy that is already resolved can keep showing up in AI answers long after it's no longer relevant.

She shared the example of how a day and a half after a notorious terror attack, she asked ChatGPT if the area had ever experienced a tragedy of that type. It replied that it had not." The model wasn't being careless, but it just hadn't updated to include the latest news. This gap between what reality is and what AI still believes is true sums up the content freshness problem.

Dr Nici Sweaney, founder of AI Her Way, explained on the same panel why this gap matters. She calls AI "an accidental narrator" — it shapes what people believe about your organisation just by repeating the latest information it received. The system simply uses what's available and is not trying to be harmful, so it's important to make sure that information is up to date.

How does this change the way organisations show up?

For PR and communications teams, this changes what "reputation management" means. Put simply, messaging that an LLM cites will remain relevant, no matter when it dates from. Messaging that has not been factored into the LLM’s answers, meanwhile, will have no discernible impact on an increasingly vital - even central - channel, regardless of how many other metrics it might win out on. 

This leads to two important things to consider:

  • First, the conditions that surround recent earned media, statements, and announcements determine whether an AI model updates its picture of the brand, or keeps running on an outdated one. Catherine Arrow of the PR Knowledge Hub made a related point on the "Inside the AI Shift" webinar: LLMs and the agents built on them are "often forbidden from going behind paywalls, from scraping particular sites," which she said creates a kind of "news vacuum." The same logic applies to the brand’s own newsroom or press page. If it isn't feeding the model something current, the model has nothing current to draw from.
  • Second, owned content—like blog posts, media releases, and website pages — are strategically important because they’re something the organisation in question can control , but only if they are updated. If a page hasn't changed in eighteen months, it's much more likely to disappear from AI results, making any reputation built on it unstable. If something is published once and not updated, the brand risks letting older, less positive stories take its place.

For public sector and government communicators, the stakes are more immediate again. When a government agency's guidance changes, whether that's eligibility criteria, compliance requirements, or a service update, and the fresh version doesn't make it into what AI models are citing, people will still get fed old information, with potentially devastating real-world implications. 

The evidence is already there

This is not just in theory. It's playing out in global research and in the day-to-day data right now.

  • AI is quietly replacing the front door to your content

The Reuters Institute's Digital News Report Australia 2026 confirms that many PR teams have noticed that Google organic search traffic to news sites dropped by a third worldwide between November 2024 and November 2025, and by 38% in the US, as AI Overviews and AI Mode launched. Publishers expect this traffic to nearly halve again in the next three years. Some now call this trend a move towards "Google Zero." For communications teams, this means people are increasingly less likely to  click through to your website to check if information is current. More often, they're trusting what the AI says: hence why it’s so important to monitor content freshness.

  • AI models are now web-enabled and they might not actually guarantee source accuracy

One challenge is that most major chatbots are now web-enabled. For example, ChatGPT can browse the internet, Gemini uses Google Search, and Perplexity has its own live index. This makes it easy to assume that AI always knows the latest information. However, this does not mean that they are always accurate when it comes to citations. A study from Columbia's Tow Center for Digital Journalism tested eight AI search tools with 1,600 queries. They found that these tools failed to correctly identify or cite the source article more than 60% of the time. Some tools were wrong on most tests and rarely showed any uncertainty. New information has not had time to be checked or confirmed like older stories have. This is the real risk of relying on the newest updates — a story that is fast moving and poorly sourced about your organisation might end up in an AI answer before it’s even verified or fact-checked. 

  • People are turning to AI chatbots specifically for what's new

The same report found that 35% of people who use AI chatbots for news do so to get the latest media updates. Dr Sora Park from the University of Canberra's News and Media Research Centre explained on the "Digital News Report Australia 2026" webinar that the main reason people use AI chatbots for news is that "AI collates stories from different news sources into a single response." People expect these tools to provide current information. If your organisation's newest content isn't included (and you have something current or novel to communicate) you miss the chance to reach audiences when they're most interested.

  • Fresh content doesn’t always equate to ‘new’ content

A notable example  of creating freshness that LLMs reward and prioritise comes from updating existing pages, rather from creating brand-new content. Republishing and refreshing current material is more effective than many communications teams realise, as long as one actually updates the content, not just the date.

  • Evergreen pages are the first casualties when AI overviews roll in

The DNR Australia 2026 report also notes that once someone is inside an AI chatbot conversation, they rarely leave it to check the source — only 4% of AI chatbot users say they always or often click through to the original article, compared with 19% for search and 17% for social media. The pages that used to earn traffic just by sitting there, permanent and useful, are now the ones most likely to lose visibility, because AI models favour what's recent over what's merely correct.

  • One fresh statement doesn't automatically undo a stale narrative

If an executive online, especially one who has a lot of weight to what they post online, says something controversial and it quickly spreads across media articles, social media and search — it will definitely be picked up by AI as well. There is a golden window of opportunity that they need to capitalise on to clarify what they said. If they don’t, the negative story that was already built into the data AI models use, will not be affected much by the executive’s clarification statement, which wasn’t that timely anyway. As Catherine Arrow of the PR Knowledge Hub said on the "Inside the AI Shift" webinar: "public relations and media relations are not the same thing," and relying on a single release misses the point. The real lesson is not to publish faster after a crisis, but to build a strong, up-to-date presence before you need it. In our latest report, “How can leaders communicate in an age of scrutiny”, we’ve outlined exactly how comms leaders can communicate by adapting their content to audiences exposed to the “AI way” of news dissemination. 

What PR & Comms teams should actually do?

The challenge is that organisations can't make an AI model update its answers whenever they want. What they can do is track whether recent work is actually being noticed, which is what  Lumina AI View can help with.

Lumina AI View monitors which sources AI models use when talking about your organisation, how strong and recent those sources are, and how you compare to competitors. Freshness is one of five key factors in the overall score. If your freshness score drops, it's an early warning that your latest campaign or announcement hasn't reached the AI ecosystem yet, and older stories are still dominating.

What’s important to note is that the tool provides a list of source citations, paired with reputation pillars like direction, integrity, performance and innovation — giving a comms professional a fully-rounded understanding of what they need to do. It’s not just the case of knowing source citations, but also of understanding your own AI perception and performance to make informed decisions — whether that’s for a brand,a government agency, a NFP or elsewhere.

This kind of tracking is even more important because it shifts by industry and by market, so "AI visibility" doesn't mean the same monitoring job for every organisation. AI answers for healthcare might draw from the smallest, highest-trust pool of sources (mostly clinical and government), but SaaS and fintech answers lean heavily on editorial reviews and comparison sites.  Ngaire Crawford made a similar point regionally on the "AI as a Stakeholder" panel. For the APAC region specifically, she pushed back on the assumption that editorial media dominates AI citations — "there are a lot of really massive claims about the impact of editorial media... some as high as 85, 88%. That's not what we're seeing." Instead, she found "a fairly even split between (editorial media) and company content," alongside a real presence for review sites, forums, and academic sources. For a comms team, that means the freshness strategy that works for a media-heavy consumer brand might not work for a government agency whose AI visibility is really riding on review sites, .gov pages, or industry forums instead.

By tracking regularly — weekly or as a routine check— you turn the vague concern of "what is AI saying about us" into something that is super clear. You can see if recent coverage changed your list of citations, or if your owned content is still being found, or where there are gaps that need to be filled because old stories still exist and are causing problems.

The opportunity in staying current

There's a real advantage here too. If old content keeps you tied to an outdated story, fresh content is a direct way for PR and communications teams to influence how AI presents them. Publishing regularly, keeping your own pages updated, and getting recent, credible coverage is not just for human audiences. It's how PR professionals can make sure the systems shaping first impressions have the right information.

Teams that make it an ongoing habit of checking in regularly, watching for changes, and keeping fresh, credible content flowing, will have more control over how AI describes their organisation.


If you would like to know more about our Lumina suite, please reach out here and our team will get in touch with for you a quick demo.

" ["post_title"]=> string(60) "Why is content freshness the new currency for AI visibility?" ["post_excerpt"]=> string(172) "AI summaries are replacing websites as your organisation's first impression. Here’s why content freshness—and the sources feeding these models—matters more than ever." ["post_status"]=> string(7) "publish" ["comment_status"]=> string(4) "open" ["ping_status"]=> string(4) "open" ["post_password"]=> string(0) "" ["post_name"]=> string(59) "why-is-content-freshness-the-new-currency-for-ai-visibility" ["to_ping"]=> string(0) "" ["pinged"]=> string(0) "" ["post_modified"]=> string(19) "2026-08-20 02:44:18" ["post_modified_gmt"]=> string(19) "2026-08-20 02:44:18" ["post_content_filtered"]=> string(0) "" ["post_parent"]=> int(0) ["guid"]=> string(32) "https://www.isentia.com/?p=49408" ["menu_order"]=> int(0) ["post_type"]=> string(4) "post" ["post_mime_type"]=> string(0) "" ["comment_count"]=> string(1) "0" ["filter"]=> string(3) "raw" }
Blog
Why is content freshness the new currency for AI visibility?

AI summaries are replacing websites as your organisation’s first impression. Here’s why content freshness—and the sources feeding these models—matters more than ever.

Ready to get started?

Get in touch or request a demo.