Indonesia Personal Data Protection Law (UU PDP)
Law No. 27 of 2022, effective October 2024. Grants data subject rights for access, correction, deletion, and portability. Breach notification required within 14 days.
| Jurisdiction | Indonesia |
|---|---|
| Category | Privacy & Data Protection |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
Indonesia’s Personal Data Protection Law (PDP Law / UU No. 27 Tahun 2022) is a comprehensive, GDPR‑style framework governing personal data processing in Indonesia, effective from 17 October 2022 with a two‑year transition period ending 17 October 2024. Organizations must now be in full compliance with requirements on legal bases, data subject rights, security, breach notification, governance, and sanctions. According to the PDP Law text (UU No. 27 Tahun 2022) and official summaries such as the Library of Congress Global Legal Monitor and PwC Indonesia Legal Alert, the law is now fully enforceable and subject to administrative and criminal penalties.
Key Requirements
Scope and Applicability
- Comprehensive, cross‑sector, overarching framework for personal data protection in Indonesia, applying to public, private, and international organizations that process personal data. According to Article 2–3 of the PDP Law official text, the law applies to any person, public body, or international organization conducting personal data processing within Indonesia or outside Indonesia where such processing has legal consequences in Indonesia. This broad, extra‑territorial scope is confirmed by AWS Indonesia Data Privacy overview and ASEAN Briefing’s PDP summary.
- Extra‑territorial effect for Indonesian data subjects The law covers personal data of Indonesian subjects even when processed abroad if there are legal consequences in Indonesia, as described in Article 2(2) of the PDP Law text, and summarized in AWS Indonesia Data Privacy and ASEAN Briefing PDP Law overview.
Legal Bases & Principles for Processing
- Lawful basis requirement: personal data may only be processed on a valid legal basis (consent, contract, legal obligations, vital interests, public task, legitimate interests). Articles 20–24 of the PDP Law text set out legal grounds and obligations for lawful processing. This is explained in the Library of Congress Global Legal Monitor summary and the PwC Indonesia Legal Alert.
- Core data protection principles: transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. These principles are embedded in Articles 16–19 of the PDP Law text, and summarized by DLA Piper Data Protection Laws in Indonesia and OneTrust practical guide to Indonesia’s PDP Law.
Data Subject Rights
The PDP Law grants extensive data subject rights comparable to GDPR:
- Right to information: to clear identity of the controller, legal basis, purposes, and accountability regarding personal data processing. Articles 5–6 of the PDP Law text and the PwC Legal Alert describe the right to obtain information on identity, legal interest, purpose and utilization, and accountability.
- Right of access: to access and obtain copies of personal data. Article 7 of the PDP Law text and summaries by the Library of Congress and PwC Legal Alert confirm access rights.
- Right to rectification / modification: to complete, update, and correct inaccurate data. Article 8 of the PDP Law text provides rectification rights; this is summarized in the PwC Legal Alert.
- Right to erasure / termination of processing: including deletion or destruction of personal data and termination of processing. Articles 9–10 of the PDP Law text provide rights to terminate processing and destroy personal data, as highlighted in the Library of Congress summary and PwC Legal Alert.
- Right to withdraw consent Articles 9 and 33 of the PDP Law text allow withdrawal of consent and require controllers to cease processing; this is noted by the Library of Congress and PwC Digital Trust NewsFlash.
- Right to object to automated decision‑making and profiling Data subjects may object to decisions based solely on automated processing that have legal or significant effects, per Articles 13 and 22 of the PDP Law text and the PwC Legal Alert.
- Right to restriction / limitation of processing Article 12 of the PDP Law text gives rights to delay or limit processing; this is summarized by PwC Legal Alert and Library of Congress.
- Right to compensation for violations. Article 12 and Article 46 of the PDP Law text provide rights to claim damages; this is highlighted in the Library of Congress summary and PwC Legal Alert.
- Data portability is not as explicitly framed as in GDPR, but the combined rights of access, copies, and transfer obligations effectively enable portability‑like outcomes, according to commentary in DLA Piper’s Indonesia PDP overview and OneTrust’s practical guide.
Breach Notification
- Mandatory breach notification to data subjects and the authority within 3 x 24 hours (72 hours) of becoming aware of a breach. Article 46 of the PDP Law text requires written notification within 72 hours; this is confirmed by the PwC Legal Alert, the PwC Digital Trust NewsFlash, and ASEAN Briefing’s PDP article.
- Notification content must include nature of the data, breach circumstances, mitigation steps, and may require public communication where there is significant public impact. This requirement is stated in Article 46 of the PDP Law text and explained in ASEAN Briefing’s PDP overview and the PwC Digital Trust NewsFlash.
(Note: your prompt mentions “14 days”; the primary legal sources clearly specify 72 hours (3 x 24 hours), so organizations should implement the 72‑hour standard.)
Governance & Organizational Measures
- Data Protection Officer (DPO) requirement for certain controllers (e.g., large‑scale processing, public bodies, high‑risk processing). Article 53 of the PDP Law text requires appointment of a DPO in specified conditions; this is summarized by DLA Piper Indonesia Data Protection overview and PwC Global data protection overview of Indonesia.
- Data Protection Impact Assessment (DPIA) for high‑risk processing. Article 34 of the PDP Law text introduces DPIA obligations for high‑risk personal data, described in the PwC Digital Trust NewsFlash and OneTrust PDP guide.
- Security and organizational measures: controllers and processors must implement technical and organizational measures to protect data against unauthorized access, disclosure, alteration, and destruction. Articles 35–40 of the PDP Law text set these obligations; they are summarized in the Library of Congress Global Legal Monitor and AWS Indonesia Data Privacy overview.
Controllers vs Processors, Cross‑Border Transfers
- Distinct obligations for controllers and processors Controllers must ensure lawful processing, respond to data subject rights, implement security measures, notify breaches, and oversee processors, while processors must act only on controller instructions and implement security. These roles are defined in Articles 25–30 of the PDP Law text, and explained by AWS Indonesia Data Privacy and DLA Piper Indonesia overview.
- Cross‑border transfers: personal data may be transferred outside Indonesia only when certain conditions are met (adequate protection, binding legal instrument, or consent and safeguards). Articles 55–56 of the PDP Law text regulate overseas transfers; this is summarized in the PwC Global overview and OneTrust PDP guide.
Enforcement & Sanctions
- Administrative sanctions: written warnings, temporary suspension of activities, data deletion, and administrative fines up to 2% of annual revenue for corporations. Articles 57–60 of the PDP Law text and the PwC Digital Trust NewsFlash describe sanctions including fines up to 2% of annual revenue and suspension of operations, as echoed in the PwC Legal Alert.
- Criminal sanctions: imprisonment and criminal fines (up to Rp 5–6 billion for individuals, higher for corporations; corporate fines can be multiplied up to 10 times plus asset seizure). Articles 67–73 of the PDP Law text outline criminal offenses and penalties; this is summarized by the Library of Congress Global Legal Monitor and the PwC Digital Trust NewsFlash.
- Transition period and full enforcement from October 2024 Controllers and processors were granted two years from 17 October 2022 to achieve compliance, with full enforcement expected after 17 October 2024. This transition is stated in Article 74 of the PDP Law text, and confirmed in the Library of Congress summary, the PwC Global overview, and DLA Piper Indonesia overview.
Compliance Challenges
Organizations commonly face operational, legal, and technical challenges implementing UU PDP.
1. Interpreting Broad and New Requirements
- Novel, overarching framework: Many Indonesian organizations previously relied on sectoral rules; UU PDP’s comprehensive scope creates complexity in interpreting overlapping obligations. The umbrella nature of the law is highlighted in the PwC Legal Alert and the Library of Congress Global Legal Monitor.
- Uncertainty during early implementation due to pending secondary regulations and the gradual establishment of a dedicated Data Protection Authority. The current role of the Ministry of Communication and Informatics (Kominfo) as interim authority and expectation of a new DPA are discussed by the Library of Congress summary and DLA Piper Indonesia overview.
2. Data Mapping and Rights Fulfilment
- Difficulty identifying all data processing activities across complex systems to support rights (
Recent developments
- — The Indonesian government announced it aims to finalize the establishment of an independent Personal Data Protection Agency (PDP Agency) within 2026, which will be responsible for overseeing and enforcing the UU PDP regime and imposing administrative sanctions.[6] (source)
- — A recent legal update highlights progress on the draft Presidential Regulation to establish Indonesia’s Data Protection Authority (DPA), signaling imminent operational supervision under UU PDP and clarifying future enforcement structures.[8] (source)
- — The same update analyzes Indonesia’s cross‑border data transfer commitments in the February 2026 U.S.–Indonesia Reciprocal Trade Agreement, indicating that UU PDP implementation will be aligned with trade‑related data flow rules and may influence data export strategies for Indonesian and U.S. companies.[8] (source)
- — Recent Indonesian court rulings discussed in the update show courts are actively shaping expectations under UU PDP, including interpretations of lawful bases for processing and remedies, prompting companies to reassess risk management and litigation exposure.[8][7] (source)
- — A 2026 trends-and-developments guide notes that UU PDP is now the primary privacy framework in Indonesia, with full compliance required after the October 2024 transition and growing focus on enforcement, data subject rights, and cross‑border transfer conditions.[7][1] (source)
- — The guide reports increasing industry attention to obligations such as Data Protection Officer (DPO) appointment, DPIAs for high‑risk processing, and potential administrative/criminal sanctions, leading companies to invest in governance structures and training.[7][4] (source)
- — A 2026 ASEAN Briefing analysis underscores that all controllers and processors had to align operations with UU PDP by October 16–17, 2024, and describes detailed lawful bases, DPIA duties, and sanction regimes that are driving comprehensive compliance programs across sectors.[4][1] (source)
- — An industry-focused commentary explains UU PDP’s shift from fragmented rules to a unified GDPR‑like framework, emphasizing strict conditions for cross‑border transfers and prompting data center and cloud providers to redesign infrastructure and contracts to meet the new requirements.[3] (source)
- — A 2026 update from an international law firm notes that the two‑year transition period ended on 17 October 2024 and that UU PDP obligations, including administrative fines up to 2% of annual revenue, are now fully enforceable, leading organizations to prioritize incident response and compliance monitoring.[1] (source)
- — A legal blog reviewing UU PDP sanctions warns that, with grace periods over, companies face multi‑layered administrative and severe criminal penalties (including large fines and potential corporate dissolution), which has intensified board‑level attention and accelerated privacy compliance initiatives in Indonesia.[2] (source)
Related regulations
- UK Data Protection Act 2018 — United Kingdom, Active
- Texas Data Privacy and Security Act (TDPSA) — Texas, Active, effective 2024-07-01
- General Data Protection Law (LGPD) — Brazil, Active, effective 2020-09-18
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Oregon Consumer Privacy Act (OCPA) — Oregon, Active, effective 2024-07-01
- Montana Consumer Data Privacy Act (MCDPA) — Montana, Active, effective 2024-10-01
- New Hampshire Privacy Act (NHPA) — New Hampshire, Active, effective 2025-01-01
- Nebraska Data Privacy Act (NDPA) — Nebraska, Active, effective 2025-01-01
Put it into practice
- Generate the policy: GDPR policy generator (generatepolicy.com)
- Buy the policy pack: Privacy Program Bundle (cyberpolicy.shop)
- Build it yourself: Privacy Dual Coverage Bundle (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates