Asia-Pacific Indonesia

Indonesia PDP Law: Compliance with Law No. 27 of 2022

Indonesia's Personal Data Protection Law: scope, GDPR-style bases, 3x24-hour breach notification, 2% revenue fines, criminal penalties, and the pending supervisory agency.

Regulation

Law No. 27 of 2022 on Personal Data Protection (enacted 17 October 2022; fully applicable from 17 October 2024)

Max Penalty

Administrative fines up to 2% of annual revenue; criminal penalties up to 6 years imprisonment and IDR 6 billion

Enforcing Authority

Personal data protection agency under the President (pending); Ministry of Communications and Digital Affairs (Komdigi) meanwhile

Official Source

www.komdigi.go.id

Executive Summary

  • Law No. 27 of 2022 (UU PDP) is Indonesia's first comprehensive privacy law, enacted 17 October 2022 with a two-year transition that ended 17 October 2024.
  • It is GDPR-modeled: controllers and processors, six lawful bases including legitimate interests, specific-data (sensitive) categories, DPIA duties, conditional DPO requirements, and extraterritorial reach where processing has legal effects in Indonesia.
  • Breach notification is unusually fast: written notice to the affected data subjects and the supervisory institution within 3x24 hours (72 hours), with public disclosure for breaches disrupting public services.
  • Administrative fines reach 2% of annual revenue plus processing suspension and deletion orders; criminal offenses (unlawful collection, disclosure, falsification, and selling of personal data) carry up to 6 years and corporate fines to IDR 60 billion.
  • The dedicated supervisory agency the law mandates has not yet been established; implementing regulations remain in draft, with Komdigi handling the interim, so enforcement architecture is still forming.

Indonesia passed its privacy law under pressure: a string of massive 2022 leaks, SIM-card registration data, election rolls, the “Bjorka” hacker’s taunting sales of government datasets, pushed a decade-old draft through parliament in weeks. The result, Law No. 27 of 2022, is the GDPR template adapted to the world’s fourth-largest population, with two Indonesian signatures: criminal provisions aimed squarely at the data-selling economy, and an enforcement architecture, a presidential supervisory agency, that the government has yet to build. The obligations are live; the enforcer is still being assembled.

RegulationLaw No. 27 of 2022 (UU PDP), fully applicable 17 October 2024
Max penalty2% of annual revenue (admin); 6 years / IDR 6B, corporate x10 (criminal)
SupervisorAgency pending; Komdigi interim
ModelGDPR-derived

The GDPR skeleton with Indonesian joints

Controllers and processors carry familiar duties: lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests), purpose limitation, minimization, accuracy, security, retention limits, and records. Data subject rights include information, access, correction, deletion, withdrawal, objection (including to automated decisions), restriction, and portability, plus compensation claims. DPIAs are mandatory for high-risk processing including all specific-data processing; DPOs are required where processing is for public services, requires large-scale regular monitoring, or involves large-scale specific data.

The deltas worth engineering for: the 72-hour breach clock runs to data subjects as well as the regulator, and has no explicit risk threshold; child data is categorically specific data; and financial data’s sensitive status pulls payments and lending into the heightened track. Consent must be explicit, in Indonesian or accompanied by translation, and unbundled from other matters.

Living with an unfinished regime

Until the RPP lands and the agency exists, three practices manage the ambiguity. Build to the statute, not the gap: obligations apply since October 2024, and retroactive leniency is not promised. Watch Komdigi and the RPP drafts: fine mechanics, transfer procedures, and DPO qualifications will arrive there, and existing sector rules (OJK for financial services, health regulations) already impose overlapping duties. Prepare evidence, not just policies: DPIA records, consent logs, breach runbooks with the 3x24-hour drill, and processor contracts, the artifacts any new agency will request first.

For regional architecture, Indonesia slots alongside Thailand’s GDPR-derived regime and contrasts with Vietnam’s consent-absolutist decree. Test your Indonesia-facing surfaces with a free scan.

Frequently Asked Questions

Is the PDP Law fully in force?

Yes as law: the transition period ended 17 October 2024, so obligations formally apply. But the implementing regulation (RPP PDP) is still being finalized and the supervisory agency has not been stood up, so detailed procedures (fine mechanics, transfer approvals, DPO specifics) and an active enforcer are pending. Sound posture: comply to the statute's text now, track the RPP for procedure.

Who does it apply to?

Any person, corporation, or public body processing personal data within Indonesia, and outside Indonesia where the processing has legal consequences in Indonesia or affects Indonesian data subjects abroad. There is no turnover threshold; scope questions turn on the data and effects, not entity size.

What counts as 'specific' (sensitive) data?

Health data, biometric data, genetic data, criminal records, child data, personal financial data, and other data specified by law. Processing it triggers heightened duties, including mandatory DPIA, and the criminal provisions weigh it in sentencing. Financial data's inclusion is broader than GDPR and captures much fintech processing.

What are the breach obligations?

Notify affected data subjects and the supervisory institution in writing within 3x24 hours of a failure of personal data protection, stating the data involved, when and how it occurred, and handling and recovery efforts. Breaches disrupting public services add a public-announcement duty. There is no risk-threshold filter in the statute's text, making Indonesia's clock one of the strictest as written.

What transfer rules apply?

Article 56 layers three options: transfers may proceed if the destination has equal-or-higher protection; failing that, with adequate and binding safeguards; failing that, with the data subject's consent. Pending the RPP's detail, practice mirrors GDPR: assess destination law, paper transfers with contractual safeguards, and reserve consent as fallback.

Can individuals or the state pursue data sellers criminally?

Yes. The PDP Law criminalizes unlawfully obtaining or collecting personal data for gain (up to 5 years), unlawfully disclosing (up to 4 years), falsifying (up to 6 years), and selling or buying personal data (up to 5 years), with corporate penalties up to 10x the fines plus dissolution. These respond directly to Indonesia's data-broker and leak economy, including the 2022 'Bjorka' leaks that accelerated the law's passage.

Regulatory Crosswalk

GDPRIndonesia PDP Law

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.