Rahmat Wibowo accused FOMO Indonesia of operating without legal entity, trademark, or PSE registration, framing it as noncompliant with Indonesia's UU PDP data protection law and warning professionals that their data lacks enforceable protection on the anonymous forum.

Original post ↗

Rahmat Wibowo accused FOMO Indonesia of operating without legal entity, trademark, or PSE registration, framing it as noncompliant with Indonesia's UU PDP data protection law and warning professionals that their data lacks enforceable protection on the anonymous forum.

Transcript

Is Your Data Safe on Anonymous Forums? A Case Study on FOMO Indonesia and Indonesia's Personal Data Protection Law Rahmat Wibowo - June1,2026 is Your Data Safe ion Anonymous Forums?. UU No. 27 Tahun 2022 : Personal Data- Platform Accountability Indonesia has entered anew era of data governance. With the enactment of Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP), every platform operatingin Indonesian digital space — domestic or foreign —is now legally bound to protect the personal data of its users. The lawis comprehensive. The obligations are real. The penalties are steep. Yet a significant portion of Indonesia's digital ecosystem still operatesina grey zone: platforms with no registered legal entity, no trademark protection, no PSE (Penyelenggara Sistem Elektronik) registration with the Ministry of Communication and Digital Affairs (Komdigi). The platform |want to focus on today is FOMO Indonesia — an anonymous professional forum that, based on publicly available records, appears to lackall three of these fundamental legal foundations. What UU PDP actually requires Let me ground this in the actual text of the law. FOMO Indonesiais a platform that collects personal data: account information, professional background, behavioral data, and potentially sensitive data disclosed in anonymous posts Under UU PDP, any entity that determines the purpose and means of processing this data is a Pengendali Data Pribadi (Personal Data Controller). Here is what the law demands of them: Pasal 20 ayat (1) — Dasar pemrosesan “Pengendali Data Pribadi wajib memiliki dasar pemrosesan Data Pribadi." Translation & implication: Every data controller must have a lawful basis for processing personal data — explicit user consent, contractual necessity, legal obligation, or legitimate interest. An anonymous platform collecting professional data without a clear privacy policy and documented consent mechanismis already in breach of this foundational article Pasal 46 ayat (1) — Kegagalan pelindungan data "Dalam hal terjadi kegagalan Pelindungan Data Pribadi, Pengendali Data Pribai wajib menyampaikanpemberitahuan secara tertulis paling lambat 3 x 24 jam kepada Subjek Data Pribadidan lembaga.” Translation & implication: Inthe event of a data breach, the controller must notify both affected users and the supervisory institution within 72 hours. If FOMO Indonesia suffers a breach — exposing the real identities behind "anonymous" accounts — there is no clearresponsible party, no legal entity to serve notices to, and no compliance mechanism in place. Pasal 35 & 36 — Keamanan dan kerahasiaan data "Pengendali Data Pribadi wajib melindungi dan memastikan keamanan Data Pribadii yang diprosesnya... wajib menjaga kerahasiaan Data Pribadi." Translation & implication: The controller must actively protect data security and maintain confidentiality. Foran anonymous forum, this is the most critical obligation. The entire value proposition of FOMO Indonesia rests on anonymity — yet thereis no auditable security framework to guarantee it. Pasal 57 ayat (3) — Sanksi administratif "Sanksi administratif berupa denda administratif paling tinggi 2 (dua) persen dari pendapatan tahunan atau penerimaan tahunan terhadap variabel pelanggaran." Translation & implication: Administrative fines canreach 2% of annual revenue. And beyond administrative sanctions, Pasal 67 provides criminal penalties of up to 5 years imprisonment and fines of Rp 5 billion for the unlawful collection oruse of personal data belonging to others The anonymity paradox: why this matters most on anonymous platforms There is a deeply problematic irony here that professionals must understand before trusting any anonymous forum with their data. These platforms promise confidentiality as their core feature. But that promise is only as strongas the legal and technical infrastructure behind it. Consider the following scenario. A professional shares sensitive information onFOMO Indonesia: details about a workplace dispute, a salary figure, a complaint about their employer. Under UU PDP Pasal 4, this could constitute personal data — and if combined with other identifying information, it reaches the threshold of data that can identify an individual. Now imagine a breach. The platform has no legal entity, no incident response plan mandated by Pasal 46, and no Data Protection Officer (DPO) as required by Pasal 53 for platforms processing large-scale data. Who do you hold accountable? The PSE gap: aregulatory blind spot Komdigi must close PSE registration under Permenkominfo No. 5 Tahun 2020 is not optional for digital platforms operating in Indonesia Itis a prerequisite for legal operation. A search of the Komdigi PSE private sector registry shows FOMO (explorefomo .id and FOMO APP —but these are registered under PT Salvus Prima Niaga, a separate entity. The anonymous forum product positioned as a professional social platform on Linkedin appears to operate outside this registration framework. Unregistered PSEs canbe blocked by Komdigi. More critically, they have no legal standing to process Indonesian citizens’ personal data under the framework UUPDP establishes. Users who participate in these platforms do so with no enforceable data rights. What professionals should do before joining any anonymous forum Acallto platform builders If youare building a digital product in Indonesia — especially one that promises privacy or anonymity — the era of informal operation is over. UU PDPisnot aspirational. Its transitional provisions (Pasal 74) gave operators two years from enactment in October 2022 to comply. That grace period has passed. Registeryour legal entity. Registeras a PSE. Appoint a DPO if you process large- scale or sensitive data. Draft a compliant privacy policy grounded in the sixlawful bases of Pasal 20. Build a breach notification protocol that can meet the 72-hour window of Pasal 46. These are not bureaucratic burdens — they are the foundations of user trust, whichis the only currency that matters in a platform. business The observations in this article are based on publicly available information from the KomdigiPSE registry, the DJKI (Pangkalan Data Kekayaan Intelektual) trademark database, and the FOMO Indonesia Linkedin page as of May 2026. This article is written for informational and public interest purposes and does not constitute legal advice. If youare a platform operator, please consult a qualified Indonesian legal counsel for compliance guidance under UU PDP. References: UU No, 27 Tahun 2022 tentang Pelindungan Data Pribadi- Permenkominfo No. 5 Tahun 2020: pse.kominfo.go.id pdki- indonesia.dgip.go.id #UUPDPindonesia#PelindunganDataPribadi#DataPrivacy#PersonalDataProtection#UUNo27Tahun2022#DigitalGovernance# TechLaw#HukumTeknologi# CyberLaw#PSEKomdigi# Komdigi# Digitallndonesia# DataBreach# CyberSecurity#PrivacyRights#AnonymousPlatform# StartupIndonesia# Techindonesia#EkonomiDigital#InfraLoka#Professionallndonesia#LinkedInindonesia