Data breaches and the 72-hour notification duty under Indonesia’s PDP Law

When personal data is exposed, Article 46 (Pasal 46) of Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) gives the data controller no more than 72 hours (3x24 jam) to deliver written notice. That is very little time to work out what happened. Organizations that have agreed their response in advance are in a much stronger position when the regulator examines the incident or a dispute follows.

The controller (Pengendali Data Pribadi) is the organization that decides how the data is used.

Who must be told

The law’s term for a breach is a “personal data protection failure”. When one occurs, the controller must deliver written notice no later than 72 hours to:

  • the affected data subjects, meaning the people whose data was exposed, in clear, non-technical Indonesian; and
  • the PDP authority (lembaga PDP).

In certain circumstances, the controller must also notify the public.

When does the clock start?

This point still needs to be confirmed against implementing regulations. Until it is, the cautious approach is to count from the moment the incident becomes known, not from when the forensic investigation is complete.

What the notice must contain

At a minimum, the notice must state:

  • which personal data was exposed;
  • when and how it was exposed;
  • what the controller has done to respond and recover.

It is good practice to add the estimated number of people or records affected, contact details for your data protection officer (DPO), the likely impact (such as fraud or phishing), and the steps people can take, such as resetting passwords and watching their accounts.

The first 72 hours, step by step

The plan we recommend to clients runs in six stages:

  1. Contain the incident in the first six hours. Isolate affected systems, revoke keys and credentials, and take forensic snapshots so evidence is preserved.
  2. Between six and 24 hours, assess what happened. Identify the categories and volume of data, judge the risk to people, and decide whether public notification is required.
  3. Before the 72 hours are up, send the PDP authority an initial report. Updates can follow as you learn more.
  4. Within the same 72 hours, notify the affected people. Use encrypted email and give call center details. Avoid links, which criminals can imitate in phishing messages.
  5. Fix the cause. Patch, rotate credentials and harden systems, and record the evidence in your incident report.
  6. After the incident, update your record of processing activities (ROPA) and data protection impact assessment (DPIA), and document the lessons learned for audit.

What late notice can lead to

Failing to meet the notification obligation can lead to administrative sanctions from the PDP authority, ranging from a written warning to an administrative fine of up to 2% of annual revenue. Where the incident involves unlawful acts, such as unlawfully obtaining or disclosing personal data, the people responsible may face criminal penalties (Articles 67-73).

A documented forensic timeline, showing what you knew and when, becomes evidence in your defense. The PDP Law sanctions guide covers the penalties in more detail.

Get ready before you need it

Prepare a “breach envelope” now: notification templates, contact details for the PDP authority, and a list of your processors. Then run a tabletop exercise every six months. In a tabletop, the response team talks through a simulated breach around a table, which shows who does what long before a real one happens.