Indonesia PDPA: UU PDP No. 27/2022 — Fully Effective Since October 2024
Indonesia's Personal Data Protection Law — Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP) — was enacted on October 17, 2022, following years of legislative development. The law came with a two-year transition period, making it fully effective and enforceable from October 17, 2024. Indonesia, with approximately 280 million people, is Southeast Asia's largest economy and one of the world's fastest-growing digital markets — home to Gojek, Tokopedia, GOTO, Traveloka, and a thriving fintech ecosystem regulated by OJK (Otoritas Jasa Keuangan). UU PDP applies to any entity processing personal data of Indonesian residents, regardless of where the processor is located — making extraterritorial compliance essential for any organisation with Indonesian users, customers, or employees.
Regulatory Framework: BSSN, Komdigi, OJK, and Bank Indonesia
UU PDP establishes a multi-regulator enforcement structure. The primary authorities are:
- BSSN (Badan Siber dan Sandi Negara — National Cyber and Crypto Agency): Responsible for cybersecurity standards, technical guidance (SNI ISO/IEC 27001, KAMI index), critical infrastructure protection, and coordinating breach response. BSSN receives breach notifications and conducts cybersecurity assessments.
- Komdigi (Kementerian Komunikasi dan Digital — Ministry of Communication and Digital, formerly Kominfo): Administers UU PDP broadly — registration of electronic system providers (PSE under Permenkominfo No. 5/2020), DPO registrations, DPIA submissions, complaint handling, and administrative enforcement (administrative sanctions Art. 57). Acts as the primary UU PDP compliance authority.
- OJK (Otoritas Jasa Keuangan): Sector-specific data governance for financial services — POJK No. 38/POJK.03/2016 (banking data governance), SEOJK 4/2021 (cybersecurity for banking/finance), fintech data rules. OJK enforcement overlays UU PDP for regulated entities.
- Bank Indonesia: Payment system data rules — GBI 23/6/DPSP payment system localisation; digital payment infrastructure data requirements.
Criminal enforcement falls under the Ministry of Law and Human Rights / National Police for prosecuting violations under Arts. 67–73 UU PDP. The maximum criminal penalty — IDR 60 billion (approximately USD 3.7 million) plus 6 years imprisonment — applies to intentional unlawful transfer of specific (sensitive) personal data (Art. 71). Corporate criminal liability allows fines up to 10× the individual maximum.
Scope and Personal Data Classification
UU PDP Art. 2 establishes extraterritorial scope: the law applies to any person (natural or legal) processing personal data of Indonesian residents, whether inside or outside Indonesia, as long as the data subjects are Indonesians or the processing relates to goods/services offered in Indonesia. Key classifications:
- General personal data (data pribadi yang bersifat umum): Name, gender, citizenship, religion, marital status, health data (general), and other basic identification information
- Specific personal data (data pribadi yang bersifat spesifik): 8 categories requiring enhanced protection — health/medical data, biometric data (used for identification), genetic data, sexual life/sexual orientation, political views, religious or philosophical beliefs, financial data and criminal records, and children's personal data
Six Lawful Bases and Consent Architecture
Article 20 UU PDP establishes six lawful bases for processing: (1) consent (persetujuan), (2) contractual necessity, (3) legal obligation, (4) vital interests of the data subject, (5) public task / exercise of official authority, and (6) legitimate interests. Article 22 specifies five conditions for valid consent: freely given, specific, informed, unambiguous, and for a single stated purpose. Separate explicit consent is required for each category of specific/sensitive personal data — blanket consent covering multiple sensitive categories is insufficient. Consent may not be a condition for receiving a service where the processing is not essential to that service.
Consent withdrawal (Art. 24): data subjects can withdraw consent at any time. The controller must process the withdrawal and cease processing within a reasonable period. No detriment or discrimination may result from withdrawal — though the controller may communicate that withdrawal affects the service that can be provided. Controllers must maintain consent records: timestamp, method, scope, and withdrawal history.
Eight Data Subject Rights — 3-Working-Day Response
UU PDP Arts. 5–18 establish eight data subject rights with a default 3-working-day response deadline — faster than GDPR (1 month) and Thailand PDPA (30 days):
- Art. 5 — Right to access (Hak mengakses): Categories, purposes, recipients, retention; 3 working days; free for first request
- Art. 6 — Right to correction (Hak memperbaiki): Correct inaccurate/outdated data; 3 working days; third-party notification required
- Art. 7 — Right to consideration / automated decision-making review (Hak mendapatkan pertimbangan): Explanation and human review of automated decisions that significantly affect the data subject
- Art. 8 — Right to deletion/erasure (Hak menghapus): Delete when purpose complete, consent withdrawn, or processing unlawful; 3 working days
- Art. 9 — Right to restriction (Hak pembatasan pemrosesan): Suspend processing pending accuracy challenge or objection resolution
- Art. 10 — Right to portability (Hak portabilitas): Machine-readable format; transfer to another controller; 3 working days
- Art. 11 — Right to objection (Hak keberatan): Object to processing (particularly direct marketing and profiling); controller must cease or provide compelling legitimate grounds
- Art. 12 — Right to withdrawal (Hak menarik persetujuan): Withdraw consent — this right is also addressed in Art. 24
Controllers must maintain a free, accessible intake channel for all rights requests, track against the 3-working-day SLA, and publish the Komdigi complaint escalation pathway. Failure to respond within deadline is an administrative violation.
Privacy Notice and Controller Obligations
Article 32 UU PDP requires a privacy notice (pemberitahuan privasi) before or at the point of personal data collection. Required elements: controller identity and contact details; DPO contact if appointed; purposes of processing; legal basis; categories of recipients; retention period; data subject rights and how to exercise them; cross-border transfer information; and complaint mechanism. The notice must be in Indonesian (Bahasa Indonesia) — or with an accessible Indonesian translation — plain language, and updated when processing changes materially. For consumer-facing applications, the notice must be accessible from the homepage and at collection points.
Article 47 requires Records of Processing Activities (RoPA equivalent / catatan kegiatan pemrosesan): all processing activities documented with data categories, purposes, recipients, legal bases, and retention periods. These records must be available for BSSN/Komdigi inspection.
Data Protection Impact Assessment (DPIA)
Article 34 UU PDP requires a DPIA (Penilaian Dampak Perlindungan Data Pribadi) for high-risk processing: profiling at scale, large-scale sensitive data processing, surveillance, new technologies creating significant risk, and automated decisions with major effects on data subjects. DPIA content requirements: purpose and necessity, proportionality assessment, risk identification, and proposed safeguards. Completed DPIAs must be submitted to Komdigi and updated when the processing changes. Organisations should build DPIA templates and a DPIA register as part of their UU PDP compliance programme.
Data Protection Officer (DPO)
Article 51 UU PDP requires DPO (Petugas Perlindungan Data Pribadi) appointment where: the organisation processes sensitive personal data at scale, conducts systematic profiling, operates critical information infrastructure, or transfers large volumes of personal data across borders. The DPO must have data protection expertise, operate with independence, have adequate resources, and have direct access to the board. The DPO's contact details must be published (in the privacy policy and at accessible points), and Komdigi must be notified of DPO appointment and changes. Unlike GDPR's DPO — the UU PDP DPO is not personally liable for the controller's violations, but must cooperate with BSSN/Komdigi investigations.
Security Measures and 14-Day Breach Notification
Article 35 requires technical and organisational security measures appropriate to the risk — encryption, access controls, authentication, network security, physical safeguards. BSSN recommends alignment with SNI ISO/IEC 27001 and completion of the KAMI (Keamanan Informasi) index assessment for critical infrastructure operators. Annual security reviews and vulnerability management are expected for organisations handling sensitive personal data.
Breach notification under Art. 46: controllers must notify BSSN/Komdigi within 14 calendar days of becoming aware of a personal data breach — notably longer than GDPR (72 hours) or Vietnam PDPD (72 hours), but strictly enforced. Notification must include breach description, categories and approximate number of affected data subjects, likely consequences, and remediation steps. Individual data subject notification is also required within 14 days for breaches likely to cause harm — including the categories of data affected, risks, steps taken, and a controller contact point. All breaches must be logged in an incident register retained for BSSN/Komdigi inspection. Processors must notify controllers immediately on discovering a breach (Art. 54).
Cross-Border Transfer Framework and Data Localisation
Articles 55–56 UU PDP require cross-border transfer safeguards: the destination country must provide an equivalent level of protection to UU PDP, or binding contractual clauses or BCRs providing equivalent protection must be in place. A Government Regulation (PP) on cross-border transfers was expected to establish an adequacy list and model clauses — monitor Komdigi portal for updates.
Data localisation is a significant consideration for Indonesia. Government Regulation No. 71/2019 on Electronic System Implementation and Permenkominfo No. 5/2020 on Private Electronic System Providers (PSE) establish localisation rules for strategic personal data (data strategis) related to national security and critical state secrets — this must be stored in Indonesia. Sector-specific rules create additional localisation requirements: OJK POJK 38/2016 and SEOJK 4/2021 for banking/financial data; Bank Indonesia GBI 23/6/DPSP for payment system data; Ministry of Health for health records. Fintech companies, banks, and healthcare providers need separate sector-specific localisation assessments beyond UU PDP's general cross-border transfer framework.
Administrative and Criminal Penalties
UU PDP Art. 57 establishes a three-stage administrative sanctions regime: written warnings → temporary suspension of data processing activities → administrative fines up to 2% of annual income or revenue generated in Indonesia. For large-scale organisations processing data of millions of Indonesians, 2% of Indonesia revenue can be a substantial figure.
Criminal penalties (Arts. 67–73) apply to intentional violations:
- Art. 67: Intentional unlawful collection of specific (sensitive) personal data — up to 5 years imprisonment + IDR 5B fine
- Art. 68: Intentional fraudulent personal data collection — up to 5 years + IDR 5B
- Art. 69: Intentional use of personal data that doesn't match its stated purpose — up to 4 years + IDR 4B
- Art. 70: Intentional unlawful disclosure — up to 5 years + IDR 5B
- Art. 71: Intentional unlawful transfer of specific personal data — up to 6 years + IDR 60B (approx. USD 3.7M) — the most severe sanction
- Art. 73: Corporate liability — up to 10× the individual maximum fine
These criminal penalties, especially the IDR 60 billion / 6-year exposure for intentional cross-border transfer violations, make UU PDP compliance a board-level priority for any organisation with significant Indonesian data assets.
Building an Indonesia PDPA Compliance Programme
A pragmatic 90-day roadmap:
- Days 0–30: Appoint DPO and notify Komdigi; register as PSE with Komdigi (Permenkominfo 5/2020); update privacy notices for all Art. 32 elements in Indonesian; implement consent management (separate explicit per sensitive category); establish 3-working-day rights response SLA; implement 14-day breach notification procedure; map cross-border transfers and assess safeguards; review OJK/BI regulations if fintech/banking
- Days 31–60: Complete DPIAs; execute processor contracts with Art. 54 clauses; implement RoPA; data retention schedule; BSSN security measures assessment; staff training
- Days 61–90: Complete compliance programme documentation; privacy by design embedded; BSSN KAMI index; OJK POJK assessment; monitor Komdigi for PP on cross-border transfers; vendor due diligence update
Use the Indonesia PDPA Compliance Checker
ComplyKit's Indonesia PDPA Compliance Checker covers 42 key obligations across six categories: Lawful Basis & Consent, Data Subject Rights, Controller Obligations & Privacy Notice, Security & Breach Notification, Cross-Border Transfers & Processor Management, and DPO/Governance & BSSN Enforcement. Free, no account required. Generates an AI-drafted HTML compliance report with gap analysis, 90-day roadmap, and UU PDP Article references.