What Indonesia’s PDP Law (Law No. 27 of 2022) asks of your organization

Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) sets one rulebook for every organization that handles personal data about people in Indonesia. It was enacted on October 17, 2022. It covers when you may use personal data, what you must tell people, and the administrative and criminal sanctions for getting it wrong.

This guide is for directors and officials who need to decide what their organization must do. It explains what the law covers, who it applies to, and where to begin.

Why one law instead of many

Before 2022, the rules were spread across several instruments. They included the Electronic Information and Transactions Law (UU ITE), the Government Regulation on Electronic Systems and Transactions (PP PSTE), and sector rules from the Financial Services Authority (OJK) and Bank Indonesia. The PDP Law brings them together into a single standard.

Much of it will look familiar to anyone who knows the GDPR, the European Union’s General Data Protection Regulation. The PDP Law draws heavily on its principles.

Does it apply if our servers are outside Indonesia?

Often, yes. The law also covers processing outside Indonesia when that processing has legal consequences in Indonesia, or when the people concerned are Indonesian citizens living abroad. Where your servers sit does not settle the question.

What counts as personal data?

Article 4 divides personal data into two groups.

General personal data covers full name, gender, nationality, religion and marital status. It also covers personal data that, once combined, identifies an individual, such as a national identity number (NIK), address, email address or phone number.

Specific personal data (data pribadi spesifik) is the more sensitive group. It covers health data and information, biometric data, genetic data, criminal records, children’s data, personal financial data, and other data as provided by law. The law treats processing this group as high risk. That means you need a data protection impact assessment (DPIA): a written review of how the processing could harm the people involved and how you will reduce that harm.

Who has duties under the law?

The law works with four roles:

  • The data subject (Subjek Data Pribadi) is the person the data is about.
  • The data controller (Pengendali Data Pribadi) decides why personal data is processed and controls the processing. Banks, e-commerce platforms and hospitals are typical controllers.
  • The data processor (Prosesor Data Pribadi) processes data on the controller’s behalf. Cloud providers, payroll vendors and call centers usually fall here.
  • The PDP authority (lembaga PDP) is the supervisor. It is established by, and accountable to, the President, and is to be set up by Presidential Regulation. Keep an eye on official announcements, because this is the body with the power to impose administrative sanctions.

When may you use personal data?

Two conditions apply. The processing must follow the personal data protection principles in Article 16. It must also rest on at least one lawful basis, meaning a legal reason the law recognizes. Article 20 lists them:

  • valid consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protection of vital interests;
  • performance of a task in the public interest or a public service;
  • other legitimate interests, taking into account the balance of interests.

If none of these applies, the processing is unlawful.

What changed when the transition period ended?

The law gave organizations two years to adjust. That transition period ended on October 17, 2024. Since then, all processing must conform to the PDP Law, and sanctions can be applied.

Two duties tend to surface first when an organization checks itself. Controllers must record all processing activities in a record of processing activities (ROPA), a register of each way the organization uses personal data. It must be kept in a form you can produce as evidence of compliance. Contracts with processors must also contain personal data protection clauses, so older vendor contracts usually need amending.

What if we do nothing?

The PDP authority can impose administrative sanctions, and some acts, such as unlawfully obtaining or disclosing personal data, are criminal offenses. Our guide to PDP Law sanctions sets out the fines and penalties in detail, including administrative fines of up to 2% of annual income or revenue.

Where to start

Begin with a data inventory: a list of what personal data you hold, where it sits, and why you have it. Build your ROPA from that inventory. Then run a gap assessment against the controller and processor obligations in the PDP Law, so you know which gaps to close first.

If you would like outside help, Snipeyes runs a 10-day PDP Readiness Assessment under NDA. The report is written so you can take it straight to your board.