The data protection officer and the PDP authority: who needs a DPO and how complaints are handled

Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) requires many organizations to appoint a data protection officer (DPO). The DPO is the person who advises the organization on the law, checks that it is being followed, and deals with the regulator and the public on data protection matters.

Who you appoint matters as much as whether you appoint. Giving the role to an IT manager who is also the database administrator creates a potential conflict of interest, because the DPO has to judge systems that person runs. The role needs room to act objectively.

Does our organization need a DPO?

Article 53 (Pasal 53) says that controllers and processors must appoint an official or officer to perform the personal data protection function (pejabat pelindungan data pribadi) in three situations:

  • when processing is carried out in the interest of public services;
  • when their core activities require regular and systematic monitoring of personal data on a large scale, as with telecommunications companies, e-commerce platforms and payment system operators; or
  • when their core activities consist of large-scale processing of specific personal data and/or personal data relating to criminal offenses, as with hospitals, insurers and banks that process biometrics.

A controller (Pengendali Data Pribadi) decides how data is used; a processor (Prosesor Data Pribadi) handles it on the controller’s behalf. Specific personal data is the law’s sensitive category, which includes health, biometric and personal financial data.

In practice, financial services and healthcare organizations in Indonesia will almost certainly need a DPO. Government agencies should look closely at the first condition, since much of their processing serves the public.

What the DPO is there to do

Article 54 sets out the duties. The DPO:

  • informs and advises the controller or processor on complying with the PDP Law;
  • monitors and ensures compliance, including the record of processing activities (ROPA) and privacy by design, meaning privacy built into systems from the start;
  • advises on data protection impact assessments (DPIAs) and monitors how they are carried out;
  • coordinates and acts as the contact point for issues related to personal data processing, including with data subjects and the PDP authority.

The GDPR, the European Union’s data protection law, offers good practice worth borrowing. Under that model, the DPO reports directly to senior management and receives no instructions that conflict with the role. The DPO is not dismissed for performing their duties, and leads internal audits and employee training.

What is the PDP authority?

The PDP authority (lembaga PDP) is the supervisory body for the law. It is established by, and accountable to, the President. Its powers include receiving complaints, conducting examinations, facilitating out-of-court dispute resolution, imposing administrative sanctions, and international cooperation.

Keep watching official sources for news on the authority’s formation and its implementing regulations. Its procedures will shape how complaints reach you.

How a complaint moves through the system

A person with a concern about their data (the data subject) should first submit a request or complaint to your DPO. Your organization then responds within the PDP Law’s deadlines. Many requests are capped at 72 hours, or 3x24 jam. If the person is not satisfied with the answer, they can complain to the PDP authority, which may mediate or impose sanctions.

Handling complaints well at this first stage is the best way to keep them from escalating.

One way to organize the role: a bank example

A bank might set up the function like this. One DPO holds a professional privacy certification, such as CIPP/E. Each division (IT, Legal, Human Capital and Risk) names a PDP Champion who is the DPO’s point of contact on the ground. A Privacy Committee meets monthly to review issues and decisions.

This spreads the daily work across the business while keeping one accountable person at the center.

If you cannot staff the role yet

Snipeyes offers DPO-as-a-Service for organizations that need the function covered while they recruit or build up internal skills. We also run a two-day training program for PDP Champions, which includes certificates and ROPA and DPIA templates.