Aug 27, 2026
The Government of Indonesia has enacted Law No. 5 of 2026 on the Third Amendment to Law No. 2 of 2002 on the Indonesian National Police (“Law 5/2026”) on 17 June 2026. This new law is not merely an institutional reform of the Indonesian National Police (the “Police”) but also expands the Police’s authority into the cybercrime environment, a development that carries practical implications for businesses whose platforms or systems may become targets or instruments used in enforcement action.
Article 14(1)(h) of Law 5/2026 expressly establishes a statutory mandate regarding cybercrime countermeasures. The Police are given a specific mandate to implement security measures to protect citizens. This provision reflects the Police’s role as extending beyond mere law enforcement after a crime has occurred, to also encompass prevention, education, and risk mitigation efforts in cyberspace.
In addition to the provision on cybercrime enforcement, Article 14(1)(h) of Law 5/2026 also mandates the Police to coordinate with relevant ministries or government agencies. Given that cybercrime is cross-sectoral in nature, its handling frequently requires the involvement of various authorities with jurisdiction over cybersecurity, cyberspace governance, personal data protection, as well as matters relating to the financial sector. The provision is intended to facilitate easier information exchange and improve law enforcement capabilities.
Law 5/2026 also provides a new legal basis for the Police to carry out their duties and authority based on the principles of professionalism, proportionality, transparency, and accountability. Pursuant to Article 19A(3), the Police may utilise technology and scientific knowledge in the field of enforcement, including: (i) the use of body-worn cameras; (ii) surveillance cameras; (iii) artificial intelligence technology; and (iv) various other cutting-edge technologies supporting the work of the Police.
In practice, the implementation of Law 5/2026 may affect business actors, particularly those operating digital platforms. Business actors, especially electronic system operators and financial technology institutions may increasingly need to coordinate with the Police in relation to reporting, investigation, and the handling of cybercrime. Business actors should therefore ensure the readiness of their cybersecurity governance, incident response mechanisms, and internal procedures oriented toward mitigation, to support coordination with the Police and other relevant government authorities.
Overall, Law 5/2026 marks a new chapter in strengthening Police authority in cybercrime enforcement, particularly through the expanded mandate for cybercrime countermeasures, the interagency coordination mechanism, and the utilisation of technology in internal oversight grounded in the principles of professionalism and accountability. In addition, business actors should monitor forthcoming implementing regulations, as these are expected to clarify the operational scope of the Police’s cybercrime powers, coordination mechanisms, and practical compliance expectations.
Should you have any questions or require assistance in assessing how this regulation impacts your organisation, please do not hesitate to contact us at [email protected] and [email protected].