What data controllers and processors must do under Indonesia’s PDP Law
Most duties in Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) fall on the organization that decides how personal data is used. Many organizations first fail a PDP audit not because of a data breach, but because they cannot produce their record of processing activities. Under this law, documentation is your evidence.
This article lists what the law expects, in the order most organizations tackle it.
Are you a controller or a processor?
The data controller (Pengendali Data Pribadi) decides why personal data is processed and controls how. A bank, hospital or online store handling its own customers’ data is a controller.
The data processor (Prosesor Data Pribadi) processes data on the controller’s behalf. Cloud providers, payroll vendors and call centers are common examples. The same company can be a controller for its own staff data and a processor for a client’s data, so check each activity separately.
What the controller must do
Have a lawful basis, and tell people
Every processing activity needs a lawful basis: consent, contract, legal obligation, vital interests, public interest, or other legitimate interests. People must also receive transparent information, usually through a privacy notice written in clear, accessible Indonesian.
Keep a record you can show
The record of processing activities (ROPA) is a register of each way you use personal data. For each activity it records the purposes, the categories of data and data subjects, retention periods, and the security profile. Keep it ready to present during an audit.
Secure the data
The law expects data security in practice: encryption, pseudonymization (replacing names and identifiers with codes), access control and logging. Together these are the practical application of security by design, meaning protection built in from the start.
Assess high-risk processing
A data protection impact assessment (DPIA) is required for high-risk processing, such as processing specific personal data, large-scale processing, or systematic profiling. Our article on when a DPIA is required explains the triggers.
Appoint a data protection officer where required
A data protection officer (DPO) must be appointed for public services, for large-scale systematic monitoring, or for large-scale processing of specific personal data.
Keep data only as long as its purpose requires
When that time runs out, delete or anonymize the data automatically rather than relying on someone to remember.
Put processors under contract
Processor contracts need clauses on written instructions, confidentiality, and support for fulfilling data subject rights.
Send data abroad only on a lawful footing
Article 56 allows cross-border transfers only where, in this order, the destination country offers an equal or higher level of protection, adequate and binding safeguards are in place, or the data subject has given consent.
Notify failures within 72 hours
If personal data protection fails, the controller must give written notice to data subjects and the PDP authority (lembaga PDP) within 72 hours (3x24 jam). We cover this in our breach notification guide.
Processors carry their own risk
A processor that processes data outside the controller’s instructions and purposes bears responsibility for that processing, including exposure to sanctions. If you are a processor, keep the controller’s written instructions on file and push back on requests that go beyond them.
A simple way to start your ROPA
Use one row per processing activity. Here is an example for customer onboarding at a bank:
| Activity | Data categories | Lawful basis | Retention | Controls |
|---|---|---|---|---|
| Customer onboarding via mobile app | National ID number (NIK), photo, biometrics | Consent + legal obligation (anti-money laundering and counter-terrorism financing, AML/CFT) | Per financial sector retention requirements | Encryption (AES-256), role-based access (RBAC), audit log |
Start with the activities that touch the most people or the most sensitive data. A ROPA that covers those well is more useful to an auditor than a long list with empty columns.