Indonesia Personal Data Protection Law (UU PDP)

Law No. 27 of 2022, effective October 2024. Grants data subject rights for access, correction, deletion, and portability. Breach notification required within 14 days.

JurisdictionIndonesia
CategoryPrivacy & Data Protection
StatusActive
Effective date
Latest development

Analysis

Indonesia’s Personal Data Protection Law (PDP Law / UU No. 27 Tahun 2022) is a comprehensive, GDPR‑style framework governing personal data processing in Indonesia, effective from 17 October 2022 with a two‑year transition period ending 17 October 2024. Organizations must now be in full compliance with requirements on legal bases, data subject rights, security, breach notification, governance, and sanctions. According to the PDP Law text (UU No. 27 Tahun 2022) and official summaries such as the Library of Congress Global Legal Monitor and PwC Indonesia Legal Alert, the law is now fully enforceable and subject to administrative and criminal penalties.


Key Requirements

Scope and Applicability

  • Comprehensive, cross‑sector, overarching framework for personal data protection in Indonesia, applying to public, private, and international organizations that process personal data. According to Article 2–3 of the PDP Law official text, the law applies to any person, public body, or international organization conducting personal data processing within Indonesia or outside Indonesia where such processing has legal consequences in Indonesia. This broad, extra‑territorial scope is confirmed by AWS Indonesia Data Privacy overview and ASEAN Briefing’s PDP summary.

Legal Bases & Principles for Processing


Data Subject Rights

The PDP Law grants extensive data subject rights comparable to GDPR:

  • Right to information: to clear identity of the controller, legal basis, purposes, and accountability regarding personal data processing. Articles 5–6 of the PDP Law text and the PwC Legal Alert describe the right to obtain information on identity, legal interest, purpose and utilization, and accountability.
  • Right to rectification / modification: to complete, update, and correct inaccurate data. Article 8 of the PDP Law text provides rectification rights; this is summarized in the PwC Legal Alert.
  • Right to erasure / termination of processing: including deletion or destruction of personal data and termination of processing. Articles 9–10 of the PDP Law text provide rights to terminate processing and destroy personal data, as highlighted in the Library of Congress summary and PwC Legal Alert.
  • Right to object to automated decision‑making and profiling Data subjects may object to decisions based solely on automated processing that have legal or significant effects, per Articles 13 and 22 of the PDP Law text and the PwC Legal Alert.

Breach Notification

(Note: your prompt mentions “14 days”; the primary legal sources clearly specify 72 hours (3 x 24 hours), so organizations should implement the 72‑hour standard.)


Governance & Organizational Measures


Controllers vs Processors, Cross‑Border Transfers

  • Distinct obligations for controllers and processors Controllers must ensure lawful processing, respond to data subject rights, implement security measures, notify breaches, and oversee processors, while processors must act only on controller instructions and implement security. These roles are defined in Articles 25–30 of the PDP Law text, and explained by AWS Indonesia Data Privacy and DLA Piper Indonesia overview.
  • Cross‑border transfers: personal data may be transferred outside Indonesia only when certain conditions are met (adequate protection, binding legal instrument, or consent and safeguards). Articles 55–56 of the PDP Law text regulate overseas transfers; this is summarized in the PwC Global overview and OneTrust PDP guide.

Enforcement & Sanctions

  • Administrative sanctions: written warnings, temporary suspension of activities, data deletion, and administrative fines up to 2% of annual revenue for corporations. Articles 57–60 of the PDP Law text and the PwC Digital Trust NewsFlash describe sanctions including fines up to 2% of annual revenue and suspension of operations, as echoed in the PwC Legal Alert.

Compliance Challenges

Organizations commonly face operational, legal, and technical challenges implementing UU PDP.

1. Interpreting Broad and New Requirements

  • Novel, overarching framework: Many Indonesian organizations previously relied on sectoral rules; UU PDP’s comprehensive scope creates complexity in interpreting overlapping obligations. The umbrella nature of the law is highlighted in the PwC Legal Alert and the Library of Congress Global Legal Monitor.
  • Uncertainty during early implementation due to pending secondary regulations and the gradual establishment of a dedicated Data Protection Authority. The current role of the Ministry of Communication and Informatics (Kominfo) as interim authority and expectation of a new DPA are discussed by the Library of Congress summary and DLA Piper Indonesia overview.

2. Data Mapping and Rights Fulfilment

  • Difficulty identifying all data processing activities across complex systems to support rights (

Recent developments

  • — The Indonesian government announced it aims to finalize the establishment of an independent Personal Data Protection Agency (PDP Agency) within 2026, which will be responsible for overseeing and enforcing the UU PDP regime and imposing administrative sanctions.[6] (source)
  • — A recent legal update highlights progress on the draft Presidential Regulation to establish Indonesia’s Data Protection Authority (DPA), signaling imminent operational supervision under UU PDP and clarifying future enforcement structures.[8] (source)
  • — The same update analyzes Indonesia’s cross‑border data transfer commitments in the February 2026 U.S.–Indonesia Reciprocal Trade Agreement, indicating that UU PDP implementation will be aligned with trade‑related data flow rules and may influence data export strategies for Indonesian and U.S. companies.[8] (source)
  • — Recent Indonesian court rulings discussed in the update show courts are actively shaping expectations under UU PDP, including interpretations of lawful bases for processing and remedies, prompting companies to reassess risk management and litigation exposure.[8][7] (source)
  • — A 2026 trends-and-developments guide notes that UU PDP is now the primary privacy framework in Indonesia, with full compliance required after the October 2024 transition and growing focus on enforcement, data subject rights, and cross‑border transfer conditions.[7][1] (source)
  • — The guide reports increasing industry attention to obligations such as Data Protection Officer (DPO) appointment, DPIAs for high‑risk processing, and potential administrative/criminal sanctions, leading companies to invest in governance structures and training.[7][4] (source)
  • — A 2026 ASEAN Briefing analysis underscores that all controllers and processors had to align operations with UU PDP by October 16–17, 2024, and describes detailed lawful bases, DPIA duties, and sanction regimes that are driving comprehensive compliance programs across sectors.[4][1] (source)
  • — An industry-focused commentary explains UU PDP’s shift from fragmented rules to a unified GDPR‑like framework, emphasizing strict conditions for cross‑border transfers and prompting data center and cloud providers to redesign infrastructure and contracts to meet the new requirements.[3] (source)
  • — A 2026 update from an international law firm notes that the two‑year transition period ended on 17 October 2024 and that UU PDP obligations, including administrative fines up to 2% of annual revenue, are now fully enforceable, leading organizations to prioritize incident response and compliance monitoring.[1] (source)
  • — A legal blog reviewing UU PDP sanctions warns that, with grace periods over, companies face multi‑layered administrative and severe criminal penalties (including large fines and potential corporate dissolution), which has intensified board‑level attention and accelerated privacy compliance initiatives in Indonesia.[2] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates