Rahmat Wibowo accused FOMO Indonesia of operating without legal entity, trademark, or PSE registration, framing it as noncompliant with Indonesia's UU PDP data protection law and warning professionals that their data lacks enforceable protection on the anonymous forum.
| ID | ev-20260728-037 |
|---|---|
| Source | Infraloka Blog |

Transcript
Is Your Data Safe on
Anonymous Forums?
A Case Study on
FOMO Indonesia and
Indonesia's Personal
Data Protection Law
Rahmat Wibowo - June1,2026
is Your Data Safe
ion Anonymous Forums?.
UU No. 27 Tahun 2022 : Personal Data-
Platform Accountability
Indonesia has entered anew era of data
governance. With the enactment of
Undang-Undang Nomor 27 Tahun 2022
tentang Pelindungan Data Pribadi (UU
PDP), every platform operatingin
Indonesian digital space — domestic or
foreign —is now legally bound to protect
the personal data of its users. The lawis
comprehensive. The obligations are real.
The penalties are steep.
Yet a significant portion of Indonesia's
digital ecosystem still operatesina grey
zone: platforms with no registered legal
entity, no trademark protection, no PSE
(Penyelenggara Sistem Elektronik)
registration with the Ministry of
Communication and Digital Affairs
(Komdigi). The platform |want to focus on
today is FOMO Indonesia — an
anonymous professional forum that,
based on publicly available records,
appears to lackall three of these
fundamental legal foundations.
What UU PDP actually requires
Let me ground this in the actual text of
the law. FOMO Indonesiais a platform
that collects personal data: account
information, professional background,
behavioral data, and potentially sensitive
data disclosed in anonymous posts
Under UU PDP, any entity that determines
the purpose and means of processing
this data is a Pengendali Data Pribadi
(Personal Data Controller). Here is what
the law demands of them:
Pasal 20 ayat (1) — Dasar pemrosesan
“Pengendali Data Pribadi wajib memiliki
dasar pemrosesan Data Pribadi."
Translation & implication: Every data
controller must have a lawful basis for
processing personal data — explicit user
consent, contractual necessity, legal
obligation, or legitimate interest. An
anonymous platform collecting
professional data without a clear privacy
policy and documented consent
mechanismis already in breach of this
foundational article
Pasal 46 ayat (1) — Kegagalan
pelindungan data
"Dalam hal terjadi kegagalan Pelindungan
Data Pribadi, Pengendali Data Pribai
wajib menyampaikanpemberitahuan
secara tertulis paling lambat 3 x 24 jam
kepada Subjek Data Pribadidan
lembaga.”
Translation & implication: Inthe event of
a data breach, the controller must notify
both affected users and the supervisory
institution within 72 hours. If FOMO
Indonesia suffers a breach — exposing
the real identities behind "anonymous"
accounts — there is no clearresponsible
party, no legal entity to serve notices to,
and no compliance mechanism in place.
Pasal 35 & 36 — Keamanan dan
kerahasiaan data
"Pengendali Data Pribadi wajib
melindungi dan memastikan keamanan
Data Pribadii yang diprosesnya... wajib
menjaga kerahasiaan Data Pribadi."
Translation & implication: The controller
must actively protect data security and
maintain confidentiality. Foran
anonymous forum, this is the most critical
obligation. The entire value proposition
of FOMO Indonesia rests on anonymity —
yet thereis no auditable security
framework to guarantee it.
Pasal 57 ayat (3) — Sanksi administratif
"Sanksi administratif berupa denda
administratif paling tinggi 2 (dua) persen
dari pendapatan tahunan atau
penerimaan tahunan terhadap variabel
pelanggaran."
Translation & implication: Administrative
fines canreach 2% of annual revenue.
And beyond administrative sanctions,
Pasal 67 provides criminal penalties of up
to 5 years imprisonment and fines of Rp 5
billion for the unlawful collection oruse of
personal data belonging to others
The anonymity paradox: why this
matters most on anonymous
platforms
There is a deeply problematic irony here
that professionals must understand
before trusting any anonymous forum
with their data. These platforms promise
confidentiality as their core feature. But
that promise is only as strongas the legal
and technical infrastructure behind it.
Consider the following scenario. A
professional shares sensitive information
onFOMO Indonesia: details about a
workplace dispute, a salary figure, a
complaint about their employer. Under
UU PDP Pasal 4, this could constitute
personal data — and if combined with
other identifying information, it reaches
the threshold of data that can identify an
individual. Now imagine a breach. The
platform has no legal entity, no incident
response plan mandated by Pasal 46, and
no Data Protection Officer (DPO) as
required by Pasal 53 for platforms
processing large-scale data. Who do you
hold accountable?
The PSE gap: aregulatory blind
spot Komdigi must close
PSE registration under Permenkominfo
No. 5 Tahun 2020 is not optional for
digital platforms operating in Indonesia
Itis a prerequisite for legal operation. A
search of the Komdigi PSE private sector
registry shows FOMO (explorefomo .id
and FOMO APP —but these are
registered under PT Salvus Prima Niaga, a
separate entity. The anonymous forum
product positioned as a professional
social platform on Linkedin appears to
operate outside this registration
framework.
Unregistered PSEs canbe blocked by
Komdigi. More critically, they have no
legal standing to process Indonesian
citizens’ personal data under the
framework UUPDP establishes. Users
who participate in these platforms do so
with no enforceable data rights.
What professionals should do
before joining any anonymous
forum
Acallto platform builders
If youare building a digital product in
Indonesia — especially one that promises
privacy or anonymity — the era of informal
operation is over. UU PDPisnot
aspirational. Its transitional provisions
(Pasal 74) gave operators two years from
enactment in October 2022 to comply.
That grace period has passed.
Registeryour legal entity. Registeras a
PSE. Appoint a DPO if you process large-
scale or sensitive data. Draft a compliant
privacy policy grounded in the sixlawful
bases of Pasal 20. Build a breach
notification protocol that can meet the
72-hour window of Pasal 46. These are
not bureaucratic burdens — they are the
foundations of user trust, whichis the
only currency that matters in a platform.
business
The observations in this article are based
on publicly available information from the
KomdigiPSE registry, the DJKI (Pangkalan
Data Kekayaan Intelektual) trademark
database, and the FOMO Indonesia
Linkedin page as of May 2026. This article
is written for informational and public
interest purposes and does not
constitute legal advice. If youare a
platform operator, please consult a
qualified Indonesian legal counsel for
compliance guidance under UU PDP.
References: UU No, 27 Tahun 2022
tentang Pelindungan Data Pribadi-
Permenkominfo No. 5 Tahun 2020:
pse.kominfo.go.id pdki-
indonesia.dgip.go.id
#UUPDPindonesia#PelindunganDataPribadi#DataPrivacy#PersonalDataProtection#UUNo27Tahun2022#DigitalGovernance# TechLaw#HukumTeknologi# CyberLaw#PSEKomdigi# Komdigi# Digitallndonesia# DataBreach# CyberSecurity#PrivacyRights#AnonymousPlatform# StartupIndonesia# Techindonesia#EkonomiDigital#InfraLoka#Professionallndonesia#LinkedInindonesia