[codicts-css-switcher id=”346″]

Global Law Experts Logo
fintech investment indonesia

Investing in Indonesian Fintech in 2026: Cross‑border Data Transfers, Licensing and Structuring Requirements

By Global Law Experts
– posted 1 hour ago

This article is a practical 2026 compliance guide for foreign investors and counsel. It explains current licensing routes (OJK, Bank Indonesia, Bappebti), cross‑border data transfer and localisation obligations (under the Personal Data Protection Law framework), and structuring options under the foreign investment rules administered by BKPM.

Fintech investment indonesia has entered a decisive new phase in 2026, as tightened foreign investment controls, revised BKPM implementation rules and the full activation of the Personal Data Protection Law reshape how inbound capital enters the market. For in‑house counsel, founders and M&A teams, the practical consequence is that licensing, cross‑border data transfer compliance, ownership structuring and transactional due diligence can no longer be treated as separate workstreams, they must be coordinated from the outset. This guide maps the regulator‑by‑regulator requirements, explains the recent rule changes and sets out structuring options with clear trade‑offs. Read it as a practitioner checklist rather than an abstract overview.

Introduction: Why 2026 is a turning point for fintech investment in Indonesia

Indonesia remains one of Southeast Asia’s most attractive digital finance markets, but the regulatory environment governing fintech investment indonesia has become materially more demanding in 2026. Three shifts converge to create both opportunity and risk. First, BKPM (the Ministry of Investment / Downstream Industry, which operates the Ministry of Investment and BKPM functions) has refined foreign investment rules, adjusting capital thresholds and the treatment of certain digital and financial activities under the positive/priority investment framework. Second, enforcement of data governance and cross‑border transfer obligations has intensified, now underpinned by Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, “PDP Law”).

Third, the Financial Services Authority (OJK) and Bank Indonesia (BI) continue to sharpen prudential and conduct expectations across lending, payments and digital finance.

The combined effect is that market entry now turns on the interaction between four regimes, investment approval, financial licensing, data governance and corporate structuring, rather than any single filing. An investor who secures a licence but mishandles data localisation, or who structures ownership without checking the current BKPM position, exposes the transaction to enforcement and unwinding risk. This article addresses each dimension in turn: the regulatory landscape and key authorities, the recent foreign investment rule changes, regulator‑by‑regulator licensing, cross‑border data transfers and PDP Law compliance, structuring and ownership options, a transactional checklist and practical risk mitigation. Because outcomes turn heavily on the specific activity and facts, local counsel should validate every structuring decision before filing.

1. Snapshot of the regulatory landscape and key authorities

No single regulator governs fintech in Indonesia. Instead, jurisdiction is allocated by activity, and most commercially active fintechs will interact with several authorities simultaneously. Understanding which regulator covers which sub‑sector is the essential first step for any fintech investment indonesia strategy.

Roles of OJK, Bank Indonesia, the data protection framework, BKPM and Bappebti

  • OJK (Otoritas Jasa Keuangan). The Financial Services Authority supervises regulated financial services, including peer‑to‑peer (P2P) lending, now more commonly described under the “information technology‑based joint funding services” (LPBBTI) framework, securities crowdfunding, banking, and other capital‑markets and financing activities. Following the enactment of the Financial Sector Development and Strengthening Law (Law No. 4 of 2023, “P2SK Law”), OJK’s mandate has expanded, including over certain crypto and digital financial asset activities.
  • Bank Indonesia (BI). The central bank regulates the payment system, including e‑money, payment gateways and payment service providers, together with the associated technical and prudential standards.
  • Data protection and electronic systems. The government function responsible for electronic systems registration and data governance has been reorganised (the former Ministry of Communication and Informatics functions now sit within the Ministry of Communication and Digital Affairs / Komdigi). This authority administers electronic systems operator (PSE) registration, data governance and elements of cross‑border personal data transfer policy, alongside the PDP Law framework.
  • BKPM / Ministry of Investment. The investment authority administers foreign investment approvals (largely through the Online Single Submission system), capital requirements and the investment classification framework that determines whether and how much foreign ownership is permitted in a given activity.
  • Bappebti (Commodity Futures Trading Regulatory Agency). Bappebti historically regulated crypto asset trading. Under the P2SK Law, supervision of crypto assets has been transitioning to OJK, with the transfer of authority phased in. Investors offering crypto‑related services must confirm the current supervisory allocation.
Fintech sub‑sector Primary regulator(s)
P2P lending / IT‑based joint funding (LPBBTI) OJK (plus BKPM investment approval)
Securities crowdfunding OJK
Payments, e‑money, payment gateway Bank Indonesia
Remittance / money transfer Bank Indonesia
Crypto asset trading OJK / Bappebti (confirm current allocation during transition)
Capital‑markets fintech OJK
Data handling (all sub‑sectors) PDP Law framework / electronic systems authority

Because activities frequently overlap, a lending platform that also facilitates payments, for example, investors should map every function of their product against this grid before deciding on entity type or licence applications.

2. Recent foreign investment rule changes: what changed and practical impacts

Recent refinements to Indonesia’s foreign investment regime, administered by BKPM, are among the most consequential developments for market entry. While the priority investment framework (introduced by the Job Creation Law and its implementing regulations) continues to encourage foreign participation in much of the digital economy, the practical detail, capital thresholds, classification of specific financial activities and the coordination expected between investment approval and sectoral licensing, has tightened.

Summary of BKPM / Ministry of Investment updates

The most important practical points for fintech investors are as follows:

  • Capital thresholds. A foreign‑owned company (PT PMA) must meet minimum investment and paid‑up capital expectations. Historically, foreign investment has generally required a total investment value exceeding a set threshold per business line, with a separate paid‑up capital requirement. Investors should confirm the current thresholds directly with BKPM, as these figures are periodically revised.
  • Activity classification. Whether a fintech activity is open to full foreign ownership, subject to a cap, or reserved depends on how it is classified under the current investment (positive) list. Financial services and payment‑system activities are frequently subject to sectoral conditions in addition to the investment classification.
  • Licensing coordination. BKPM approval alone does not authorise regulated financial activity. Investors must align the investment approval with OJK, BI or Bappebti licensing, and inconsistencies between the two can delay or block operations.

Timeline and transitional arrangements

Where rules change mid‑cycle, transitional arrangements typically allow existing licensed entities a period to align, while new entrants are held to the current position. Practically, this means an investor acquiring an established fintech may inherit a grandfathered position, whereas a greenfield build will be assessed against the current framework in full. The practical impact for fintech investment indonesia is that M&A structuring and greenfield structuring now diverge more sharply: buyers must diligence the target’s compliance status and the durability of any legacy permissions, while greenfield investors should pre‑engage BKPM and the relevant sectoral regulator to confirm classification before committing capital.

Because the position varies by activity, verify the current thresholds and classification with BKPM and confirm the interaction with the sectoral licence before finalising the structure.

3. Licences and approvals for foreign fintechs (regulator‑by‑regulator)

Licensing is the operational core of any fintech investment indonesia plan. The route depends entirely on the activity, and most commercial fintechs will need both a sectoral licence and BKPM investment approval. Timelines below are indicative and should be treated as typical rather than guaranteed.

OJK, lending, crowdfunding and regulated financial services

OJK licenses IT‑based joint funding (P2P lending), securities crowdfunding and a range of other regulated financing and capital‑markets activities. Applicants should expect requirements covering:

  • Corporate form and local presence. A locally incorporated entity, typically a PT PMA (or in some sub‑sectors a limited liability company or cooperative as prescribed), with a registered office and qualifying local management.
  • Minimum capital. Sub‑sector‑specific capital and equity maintenance requirements, which OJK sets and periodically updates. For LPBBTI operators, OJK has prescribed minimum paid‑up capital and ongoing equity requirements, confirm the current figures with OJK.
  • Fit and proper. Assessment of controllers, directors and commissioners.
  • Systems and controls. Risk management, anti‑money‑laundering (AML) procedures, consumer protection processes and information‑system readiness.

Licensing often proceeds in stages, from registration or conditional status through to a full permit, with the timetable driven by the completeness of the application and OJK’s queue.

Bank Indonesia, payment system, e‑money and payment gateway licensing

BI regulates the payment system under a categorised licensing framework (organised broadly around payment service providers and payment system infrastructure operators). Payment service providers, e‑money issuers and payment gateway operators must satisfy capital, technical, security and operational standards, and BI applies proportionate scrutiny according to the systemic significance of the activity. Foreign‑ownership conditions in the payment sector are typically more restrictive than in some other digital activities, BI rules have applied local ownership and control expectations in parts of the payment system, so investors must confirm the permitted ownership position before designing the cap table. Technical readiness, including interoperability, security certification and data handling, is assessed as part of the application.

Crypto assets, Bappebti / OJK during transition

Where a fintech offers crypto asset trading, Bappebti historically administered the registration and licensing of crypto asset exchanges and traders, alongside physical commodity market rules. Under the P2SK Law, supervisory authority over crypto (financial digital assets) has been transitioning to OJK. Crypto‑focused investors must confirm the current supervisory allocation and the specific registration, capital and custody requirements before launch.

BKPM investment approval and the investment list

Running alongside every sectoral application is the BKPM process, conducted largely through the Online Single Submission (OSS) system. Investors register the foreign investment, confirm the activity’s classification and ownership position, and satisfy capital requirements. The BKPM approval and the sectoral licence must be internally consistent; a mismatch between the declared business activity (KBLI code) and the licence sought is a common cause of delay.

Step‑by‑step licensing checklist

  1. Map every product function to its regulator (OJK, BI, Bappebti/OJK for crypto).
  2. Confirm the activity classification (KBLI) and permitted foreign ownership with BKPM.
  3. Incorporate the PT PMA and meet capital thresholds.
  4. Prepare fit‑and‑proper documentation for controllers and management.
  5. Assemble systems, AML, consumer‑protection and information‑security policies.
  6. File the sectoral licence application with OJK, BI or the applicable authority.
  7. Align the BKPM investment approval with the sectoral licence scope.
  8. Complete any staged or conditional approval milestones.
  9. Register the electronic system (PSE registration) and address data governance obligations before go‑live.
  10. Establish post‑licensing reporting and capital‑maintenance routines.

Because procedures are activity‑specific and periodically revised, confirm the current requirements with the relevant regulator before filing.

4. Cross‑border data transfers, data localisation and PDP Law compliance

Data governance is now inseparable from fintech investment indonesia. Indonesia’s Personal Data Protection Law (Law No. 27 of 2022) governs the processing of personal data and the conditions under which it may leave Indonesia. Because fintechs are, by nature, high‑volume processors of personal and financial data, cross‑border data transfer indonesia compliance sits at the centre of operational and transactional risk.

Scope of the PDP Law and electronic systems rules

The PDP Law distinguishes between general personal data and specific (more sensitive) personal data, and imposes obligations on controllers and processors covering lawful basis, transparency, data subject rights, security and breach response. Fintechs handling identity, financial and behavioural data should assume that most of their processing falls within scope and that additional care applies to specific categories.

Data localisation triggers and exceptions

Data localisation indonesia obligations arise from the interaction between sectoral rules and the electronic systems and data governance framework. Certain financial and payment data may be subject to expectations that specified data is stored, processed or made accessible within Indonesia, for example, BI and OJK rules have imposed local data centre and processing expectations for parts of the financial and payment sectors. The precise triggers and any exceptions depend on the activity and the regulator, so investors must confirm the current position for their sub‑sector rather than assume either full localisation or full freedom to host offshore.

Mechanisms for lawful cross‑border transfers

Where personal data is transferred outside Indonesia, the PDP Law requires the transfer to rest on a recognised basis. In broad terms these include:

  • Adequacy‑style conditions. Transfers to a jurisdiction that has a level of personal data protection equal to or higher than that provided under the PDP Law.
  • Adequate and binding safeguards. Where the destination does not meet the adequacy standard, ensuring adequate and binding protection through contractual or other instruments.
  • Consent. Valid, informed and specific consent from the data subject where the other bases are not met.

Investors should design data flows and supporting contracts around these mechanisms from the start, and should embed a data processing agreement (DPA) into every vendor and intra‑group arrangement. Recommended contractual controls include clear allocation of controller/processor roles, security standards, sub‑processor approval, breach‑notification timelines, audit rights and data‑return or deletion obligations on termination. Analysis of Indonesian private international law reinforces why jurisdiction, governing law and enforceability clauses in cross‑border data contracts deserve careful drafting rather than boilerplate treatment.

Enforcement and penalties

Enforcement of the PDP Law and data governance rules has become more active. The consequences of non‑compliance range from administrative sanctions (including written warnings, temporary suspension of processing, deletion orders and administrative fines) to reputational and commercial harm, including disruption to licensed operations. For fintechs, a data breach or an unlawful transfer is not only a data‑protection failure but potentially a prudential and conduct issue engaging OJK or BI. The practical takeaway is that cross‑border data transfer indonesia compliance should be built into product architecture, vendor contracts and incident‑response planning before launch, not retrofitted after an enforcement notice.

5. Structuring and ownership options for inbound fintech investment indonesia

Choosing the right holding and operating structure is where fintech investment indonesia strategy is won or lost. The correct option depends on the permitted foreign ownership for the activity, the speed of entry required, the appetite for compliance burden and the counterparty landscape.

PT PMA, the foreign‑owned company

The PT PMA is the standard vehicle for a foreign investor seeking direct control. It permits majority or full foreign ownership where the activity allows, and it is the natural home for licence applications. The trade‑off is a higher compliance and capitalisation burden, together with the need to satisfy BKPM thresholds and sectoral conditions. For investors who want durable control and a clean licensing route, the PT PMA is usually the most robust choice.

Joint ventures and shareholder agreements

A joint venture with an Indonesian partner is frequently used where an activity carries foreign‑ownership limits or where local relationships materially assist licensing and distribution. The key to a successful JV is governance: reserved matters, minority‑protection provisions, board composition, deadlock resolution and clear exit mechanics should be negotiated in the shareholders’ agreement. Poorly drafted governance is the most common source of later dispute, so the agreement deserves the same rigour as the licensing application.

Local licence via partner, branch and representative office

Faster or lighter‑touch routes carry their own trade‑offs. Operating under a licensed Indonesian partner’s permission, a white‑label or partnership model, can accelerate market entry but transfers control of the licensed environment, and often the local data environment, to the partner. A representative office cannot conduct commercial fintech activity and is suitable only for market study or liaison. Branch structures are generally not available for most commercial fintech activities under Indonesian company and financial‑sector rules, so investors should confirm whether any branch form is permitted for the relevant activity before relying on it.

Nominee risks and mitigation

Using a nominee shareholder or director to circumvent ownership limits is legally and commercially hazardous. Indonesian company law expressly prohibits nominee shareholding arrangements, which are treated as void; such arrangements face enforceability problems and enforcement risk, and can undermine the validity of the underlying investment. Investors seeking exposure to activities with foreign‑ownership limits should instead rely on legitimate structures, properly negotiated JVs, protective shareholder agreements, service and licensing agreements, and where appropriate escrow and security arrangements, rather than concealed ownership.

Structuring option Foreign majority? Licensing impact Time to establish Data localisation implications Key risks
PT PMA (foreign‑owned company) Yes (subject to investment list) Common route; permits required Typically 2–6 months Depends on operations; can host locally Compliance burden, capitalisation
JV with Indonesian partner Yes (depending on sector) Often used to meet licensing/local requirements Typically 3–6 months May ease localisation if partner hosts Minority protection, governance disputes
Local licence via Indonesian PSP/partner (white‑label) No (depends) Faster entry under partner’s licence Typically 1–3 months Partner controls local data environment Dependency on partner, counterparty risk
Representative office (non‑commercial) No Cannot conduct commercial fintech activity N/A for commercial ops Not suitable where local hosting required Limited commercial utility
Branch (only if permitted for the activity) Limited Generally unavailable for most fintech activities Variable Must assess local data obligations Availability restrictions, higher scrutiny

6. Transactional checklist: M&A, investment and commercial contracting considerations

Where entry is by acquisition or investment rather than greenfield build, the diligence and execution workstreams broaden. A disciplined transactional process protects value and avoids inheriting hidden regulatory liabilities.

Due diligence, filings and post‑closing tasks

The following ten‑point checklist captures the core execution tasks for a fintech transaction:

  1. Regulatory diligence. Verify the target’s licences with OJK, BI or Bappebti/OJK and check for conditions, restrictions or pending enforcement.
  2. Data diligence. Review PDP Law compliance, cross‑border transfer arrangements, DPAs and any breach history.
  3. Ownership diligence. Confirm the current foreign‑ownership position for the activity and check for nominee or circumvention risk.
  4. Corporate diligence. Validate capitalisation, shareholder agreements and corporate approvals.
  5. Pre‑closing permits. Identify change‑of‑control approvals or notifications required from regulators.
  6. Competition checks. Assess whether the transaction triggers merger notification obligations to KPPU (the competition authority).
  7. Employment and data. Review key personnel, local‑management requirements and employee data transfer implications.
  8. Contractual assignment. Confirm that partner, vendor and customer contracts survive change of control.
  9. BKPM alignment. Ensure the post‑closing ownership and activity remain within the investment approval.
  10. Post‑closing compliance. Schedule licence updates, filings, capital maintenance and reporting obligations.

Sequencing matters: regulatory and data diligence should run early, because adverse findings can reshape the structure, price or feasibility of the deal.

7. Practical risk mitigation: governance, operational and contractual steps

Sustained compliance, not just entry, determines whether a fintech investment indonesia succeeds over the medium term. The following measures operationalise the obligations described above.

  • Data protection programme. Maintain a documented PDP Law compliance programme covering lawful basis, records of processing, DPAs, transfer mechanisms and data‑subject request handling.
  • Incident response. Establish a breach‑detection and notification process aligned to regulatory timelines and to any OJK/BI conduct expectations.
  • Local governance. Meet local director and management requirements and ensure the board can discharge fit‑and‑proper and oversight duties.
  • Capital maintenance. Monitor sectoral capital and equity requirements and refresh evidence of compliance as thresholds change.
  • IP and source‑code protection. Consider source‑code escrow and clear IP assignment where technology is licensed from or shared with partners.
  • Regulatory engagement. Maintain proactive lines to OJK, BI, the electronic systems authority, BKPM and Bappebti/OJK, and file required notifications on time.

Investors evaluating a controlled entry may also consider regulatory sandbox or pilot participation, where available (OJK and BI have operated sandbox mechanisms for financial innovation), to test products under supervisory oversight before full‑scale launch.

Conclusion and recommended next steps for investors

A successful fintech investment indonesia in 2026 depends on treating licensing, data governance, ownership and structuring as one integrated problem rather than four separate filings. The immediate next steps for any investor are clear: map every product function to its regulator; audit intended data flows against PDP Law and localisation requirements; use the structuring comparison table to choose between PT PMA, JV and partner‑led routes; pre‑engage BKPM and the relevant sectoral regulator to confirm classification and ownership before committing capital; and engage local counsel to validate the structure before filing. Because outcomes turn on activity‑specific facts and on rules that are periodically revised, verify the current position with the relevant authority and take advice tailored to your transaction before proceeding.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Rizki Dwianda at Karna Partnership, a member of the Global Law Experts network.

Sources

  1. OJK (Otoritas Jasa Keuangan / Financial Services Authority)
  2. Bank Indonesia
  3. BKPM / Ministry of Investment
  4. Bappebti (Commodity Futures Trading Regulatory Agency)
  5. Online Single Submission (OSS) system

FAQs

What licences do foreign fintechs need to operate in Indonesia?
It depends on the activity. P2P/IT‑based joint funding and crowdfunding are regulated by OJK; payments and e‑money by Bank Indonesia; crypto asset trading has been transitioning from Bappebti to OJK. Most commercial fintechs will also need BKPM investment approval and a PT PMA.
Transfers of personal data must satisfy the PDP Law, for example, transfer to a jurisdiction with an adequate level of protection, adequate and binding safeguards where it does not, or valid consent. Data localisation triggers under sectoral rules may require certain financial or payment data to be stored or accessible in Indonesia, so design flows and contracts accordingly.
Some fintech sub‑sectors, particularly in payments and financial services, are subject to foreign‑ownership conditions under the BKPM investment framework and sectoral rules. Review the current position with BKPM and the relevant regulator before structuring.
No. Nominee shareholding arrangements are prohibited and void under Indonesian company law, and carry serious legal, enforceability and enforcement risk. Use legitimate structures instead, properly negotiated joint ventures, protective shareholder agreements and service arrangements.
Partnering with a licensed Indonesian provider under a white‑label model is usually fastest, but transfers control of the licensed and data environment to the partner. A PT PMA with its own licences offers full control but takes longer to establish.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Investing in Indonesian Fintech in 2026: Cross‑border Data Transfers, Licensing and Structuring Requirements

Send welcome message

Custom Message