Getting consent right under Indonesia’s PDP Law
Consent is one of the lawful bases for using personal data under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP). When you rely on it, the bar is high. Consent that falls short of the law’s requirements risks being declared null and void, which leaves the processing without a legal basis.
A pre-ticked box that says “I agree to everything” is hard to defend. A good test is whether giving consent feels as clear as pressing a button that says “Yes, I allow X to do Y.”
What the law asks for
The PDP Law requires explicit, valid consent for specific purposes that have been communicated to the data subject, meaning the person the data is about. Consent must be given in written or recorded form, either electronically or non-electronically.
Turning the law into design rules
In practice, five tests will help you meet that standard:
- Clear and explicit. Consent is never implied. Silence does not count.
- One consent per purpose. Marketing needs its own consent, separate from analytics.
- Informed. Tell people, in plain and easy-to-understand Indonesian, who you are, why you want the data, which data you will use, what rights they have, and how long you will keep it.
- Freely given. Nobody is pressured. Saying no must not block the core service, unless the data is strictly necessary to provide it.
- Easy to withdraw. The button to withdraw consent should be as easy to find as the button that gave it.
Designs that do not pass
Designers call these “dark patterns”: screens built to steer people into agreeing. Each of the following undermines consent:
- A single checkbox that bundles six purposes together.
- Boxes that are ticked in advance, so the user has to untick them to refuse.
- Cookie walls that block access unless the user accepts non-essential analytics, with no alternative offered.
- Ten pages of terms and conditions full of legal jargon. This does not satisfy the requirement for informed consent.
How to fix your consent flow
Start by giving people separate choices. On a lending app, for example, that might look like three boxes: [ ] Loan profiling [ ] WhatsApp marketing [ ] Partners.
Next, keep a consent log. For each consent, record the timestamp, the version of the notice the person saw, the IP address or device, and where the consent came from. In an audit, this log is your evidence.
Finally, add a “Withdraw consent” button to the user’s account. Once someone withdraws, stop processing no later than 72 hours (3x24 jam), and make sure your processors stop too.
Health data, biometrics and children
Some data needs extra care. Processing health, biometric, genetic or personal financial data, or children’s data, is considered high risk and requires a data protection impact assessment (DPIA), a written review of the risks and how you will reduce them. Consent to process a child’s data must be given by a parent or guardian.
If you are not sure where to begin, pull up your main sign-up form and your cookie banner and check them against the five tests above. Most of the fixes are small design changes, and they are much cheaper to make before a complaint arrives.