Data subject rights under Indonesia’s PDP Law, and how to meet them on time
Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) gives every person whose data you hold a set of rights they can use against your organization. Several of these rights come with a deadline of 72 hours (3x24 jam), far shorter than many teams expect. If you cannot find, correct or stop using someone’s data in that time, you risk administrative sanctions.
A quick note on terms. The person the data is about is the data subject (Subjek Data Pribadi). The organization that decides how the data is used is the data controller (Pengendali Data Pribadi). The duties in this article fall on the controller.
What people can ask of you
Articles 5 to 13 set out the rights. In plain words, a data subject may:
- Know who is requesting their data, the legal basis, the purpose of the request and how the data will be used, and who is accountable (the right to information).
- Complete, update and correct errors or inaccuracies in their data.
- See their personal data and obtain a copy (the right of access).
- Have processing ended, and have their data deleted and/or destroyed.
- Withdraw consent they gave earlier.
- Object to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect them.
- Have processing delayed or restricted, in proportion to its purpose.
- Sue and receive compensation for violations in the processing of their data.
- Receive their data in a structured, commonly used format and send it to another controller, provided the systems can communicate securely with each other (the right to data portability).
The deletion right will be familiar from the GDPR, the European Union’s data protection law, which calls it the “right to be forgotten”. Indonesia now has a comparable right.
People usually exercise these rights through a recorded request, sent electronically or on paper. Some rights can be exempted, for example for national defense and security, law enforcement, supervision of the financial services sector, and statistics and scientific research.
How quickly you must respond
This is the part that needs the most planning. The controller’s duties to give access, to update or correct data, and to stop processing after consent is withdrawn are generally framed as no later than 72 hours from receipt of the request.
Do not assume one deadline fits every request type. Map each type against the text of the relevant article and its implementing regulations, and write the result into your procedures.
We recommend a simple internal rhythm. Triage the request on the day it arrives. Verify the person’s identity within 24 hours. Complete the request within 72 hours. Put these steps in the standard operating procedure (SOP) of your data protection officer (DPO), the person who oversees data protection compliance.
A sample acknowledgement
Replying quickly and clearly also shows the regulator you take the request seriously. An anonymized example:
We have received your request (Ticket PDP-2023-xxx). We will verify your identity via a one-time code (OTP) sent to your registered phone number and act on this request within 72 hours. If your data is also processed by our processors, we will forward the same instruction to them within that time frame.
Where organizations go wrong
- They delay or refuse a request without giving a written reason, which risks administrative sanctions.
- They ask people to send a photo of their national ID card (KTP) by unencrypted email. That goes against the law’s security and data minimization principles, which mean collecting only what you need and protecting it.
- They refuse deletion because the data sits in “internal archives”, without any retention requirement in regulation that justifies keeping it.
A test worth running this month
Ask a colleague to file a mock access request as if they were a customer. Time how long it takes your teams to find all of that person’s data, including copies held by vendors, and send it back. If the answer is longer than 72 hours, you know where to start.