Sending personal data abroad under Indonesia’s PDP Law
If your databases run in a Singapore cloud region, or your support center is in India, personal data is leaving Indonesia. Article 56 (Pasal 56) of Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) sets the conditions for that transfer. Assuming the provider is “already secure” does not meet them.
The duty sits with the data controller (Pengendali Data Pribadi), the organization that decides how the data is used.
Is this happening in our organization?
Probably. Ask your technology and procurement teams three questions:
- Are any databases, backups, logs or analytics tools hosted outside Indonesia?
- Do overseas vendors or group companies receive customer or employee data?
- Do staff paste customer data into generative AI tools such as ChatGPT, Gemini or Claude?
A yes to any of them means you have cross-border transfers to assess.
What Article 56 requires
The law sets three conditions in a fixed order. You move to the next one only if the previous one cannot be met.
- The destination country provides an equal or higher level of protection than the PDP Law. How this is assessed is to be set out in implementing regulations. It is similar to an adequacy decision under the GDPR, where the European Union formally finds that a country protects data well enough.
- If not, adequate and binding personal data protection safeguards are in place. Examples are standard contractual clauses (SCCs, template data protection terms written into the contract), binding corporate rules (BCRs, internal transfer rules that bind a whole corporate group), or other binding agreements.
- If neither is met, the controller must obtain the data subject’s consent, after informing the person of the risks of the transfer.
Consent comes last for a reason. It must be genuinely informed, and it cannot be a formality applied to thousands of records without any assessment.
A practical checklist
- Map where your data lives. Know which region holds your databases, backups, logs and analytics.
- Review cloud contracts. Confirm SCCs or binding data protection clauses, audit rights, a 72-hour (3x24 jam) incident notification clause, and named processing locations.
- For software services based in the United States, run a short transfer impact assessment (TIA). This reviews the destination country’s laws, including the government’s powers to access data.
- Add two columns to your record of processing activities (ROPA): “cross-border transfer = Yes/No” and “basis = equivalence/safeguards/consent”.
- Include generative AI tools. Customer data pasted into ChatGPT, Gemini or Claude can amount to a transfer to a foreign provider. Browser-side masking such as Nesgate removes personal data from prompts before it leaves the device.
Two mistakes to avoid
The first is treating a vendor’s ISO/IEC 27001 certificate as proof of an equal level of protection. The certificate shows the vendor runs a security management system. Article 56 asks a different question.
The second is moving large volumes of data on the strength of a generic consent tick in an app. As explained above, consent is the last resort, and it only works when people have genuinely been told the risks.