Indonesia passed its privacy law under pressure: a string of massive 2022 leaks, SIM-card registration data, election rolls, the “Bjorka” hacker’s taunting sales of government datasets, pushed a decade-old draft through parliament in weeks. The result, Law No. 27 of 2022, is the GDPR template adapted to the world’s fourth-largest population, with two Indonesian signatures: criminal provisions aimed squarely at the data-selling economy, and an enforcement architecture, a presidential supervisory agency, that the government has yet to build. The obligations are live; the enforcer is still being assembled.
| Regulation | Law No. 27 of 2022 (UU PDP), fully applicable 17 October 2024 |
|---|---|
| Max penalty | 2% of annual revenue (admin); 6 years / IDR 6B, corporate x10 (criminal) |
| Supervisor | Agency pending; Komdigi interim |
| Model | GDPR-derived |
The GDPR skeleton with Indonesian joints
Controllers and processors carry familiar duties: lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests), purpose limitation, minimization, accuracy, security, retention limits, and records. Data subject rights include information, access, correction, deletion, withdrawal, objection (including to automated decisions), restriction, and portability, plus compensation claims. DPIAs are mandatory for high-risk processing including all specific-data processing; DPOs are required where processing is for public services, requires large-scale regular monitoring, or involves large-scale specific data.
The deltas worth engineering for: the 72-hour breach clock runs to data subjects as well as the regulator, and has no explicit risk threshold; child data is categorically specific data; and financial data’s sensitive status pulls payments and lending into the heightened track. Consent must be explicit, in Indonesian or accompanied by translation, and unbundled from other matters.
Living with an unfinished regime
Until the RPP lands and the agency exists, three practices manage the ambiguity. Build to the statute, not the gap: obligations apply since October 2024, and retroactive leniency is not promised. Watch Komdigi and the RPP drafts: fine mechanics, transfer procedures, and DPO qualifications will arrive there, and existing sector rules (OJK for financial services, health regulations) already impose overlapping duties. Prepare evidence, not just policies: DPIA records, consent logs, breach runbooks with the 3x24-hour drill, and processor contracts, the artifacts any new agency will request first.
For regional architecture, Indonesia slots alongside Thailand’s GDPR-derived regime and contrasts with Vietnam’s consent-absolutist decree. Test your Indonesia-facing surfaces with a free scan.