Purpose: This study evaluates the level of Personal Data Protection (PDP) compliance among Electronic System Providers (ESPs) in Indonesia based on the Personal Data Protection Law (PDP Law) and the Government Regulation concerning the Implementation of Electronic Systems and Transactions. Methods: A descriptive-evaluative approach was conducted through observations of website and mobile application interfaces from 20 ESPs registered with the Ministry of Communication and Digital Affairs. Compliance was assessed using a binary scoring system based on six PDP indicators: consent mechanisms, privacy notices, TLS/SSL implementation, data disclosure, malicious libraries, and device data access. Descriptive statistical analysis was used to evaluate compliance levels. Instrument validity was established through content validity and expert judgment. Result: Most ESPs were classified within the moderate compliance category, covering 90% of websites and 80% of mobile applications. Governance-related indicators showed the lowest compliance levels, particularly website consent mechanisms (15%) and website privacy notices (40%) and mobile consent and privacy notice compliance (20%). In contrast, all ESPs complied with technical indicators, including TLS/SSL, malicious library, and device data access requirements. Novelty: Unlike previous studies that focused on single sectors or platforms, this study provides a cross-platform PDP compliance assessment integrating both technical and governance indicators within a single framework. The findings indicate that governance practices remain the primary challenge in PDP implementation, providing practical recommendations for regulators and ESPs in strengthening personal data protection implementation in Indonesia.
Copyrights © 2026