When your organization needs a DPIA under Indonesia’s PDP Law

A data protection impact assessment (DPIA) is a short written review of how a new use of personal data could harm the people involved, and what you will do to reduce that harm. Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP) requires controllers to carry one out whenever processing has a high potential risk to data subjects.

Skipping it is a real exposure. Launch an AI-driven credit scoring feature without a DPIA, for example, and you carry high risk with no record of having managed it. The PDP authority (lembaga PDP) has the power to impose sanctions, including temporary suspension of processing.

Does our project need one?

Run through these questions. If the answer to any of them is yes, plan a DPIA.

  • Will a system make automated decisions with legal or similarly significant effects? Credit scoring, e-KYC (electronic customer identity checks) and employee screening are common cases.
  • Will you process specific personal data, the law’s sensitive categories? These are health, biometric, genetic and personal financial data, and children’s data.
  • Is the processing large-scale?
  • Will you systematically evaluate, score or monitor people, for example with AI-enabled CCTV or facial recognition?
  • Will you match or combine groups of data from different sources?
  • Are you using new technology, such as generative AI, connected medical devices (medical IoT) or blockchain-based identity?
  • Could the processing restrict people’s ability to exercise their rights as data subjects?

What goes into a DPIA

One or two pages is usually enough. A good DPIA works through five questions in order:

  1. What are we doing? Describe the purpose, how the data flows, who is involved, and how long the data is kept.
  2. Is it necessary and proportionate? Explain why the purpose cannot be achieved with less data.
  3. What could go wrong? Rate each risk by likelihood and by impact on people’s rights, such as loss of privacy, discrimination or financial loss.
  4. How will we reduce it? List the safeguards: encryption, pseudonymization, collecting less data, access control, logging and retention limits.
  5. What risk is left? If the remaining risk is still high, postpone the launch and consider consulting the PDP authority. The formal consultation mechanism still awaits implementing regulations.

A one-page template

You can keep the core of the assessment in a single table. The example row below describes a flaw where one customer could read another customer’s profile through the app’s API (the interface the app uses to fetch data). Security testers call this broken object level authorization, or BOLA.

Risk Initial score Mitigation Residual score Owner
BOLA on customer profile API (one customer can read another’s data) High Attribute-based access control (ABAC) + mutual TLS (mTLS) + logging Low CTO

Keep it current

A DPIA describes one version of a project. Any change in purpose, technology, or a new vendor requires an updated DPIA.

A sensible first step is to list the projects your organization plans to launch this year and run each one through the questions above. That gives you a DPIA pipeline instead of a last-minute scramble before go-live.