Indonesia PDP Law
Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Indonesia PDP Controller Obligations (Art 20-46)
Articles 20-46 of UU PDP impose comprehensive obligations on Personal Data Controllers. Article 20: Personal Data Controller shall be accountable for personal data processing carried out by the Controller and demonstrate compliance with UU PDP. Article 21: Personal Data Controller shall conduct personal data processing in accordance with the purposes notified + lawful basis + consent obtained. Article 22: Personal Data Controller shall ensure accuracy + completeness + clarity of personal data processed + correct inaccuracies upon Data Subject request + or where becomes aware. Article 23: Personal Data Controller shall ensure personal data security through reasonable + appropriate technical + organisational + and physical security measures including data security policies + encryption + access controls + audit logging + secure development + incident response capability. Article 24: Person
- Accountability framework + compliance documentation + audit ready + records
- DPO appointed + independent + top-management reporting + Indonesian Representative + records
- Privacy by Design + system architecture + product development + records
- ROPA per Article 46 + comprehensive + updated + per processing activity + records
- DPIA per Article 45 triggers + high-risk + documented + mitigation + records
- Accountability claimed but no documentation (audit failure risk)
- DPO appointed but reporting to mid-management (independence compromised)
- Privacy by Design retrofitted (not integrated at design stage)
- ROPA incomplete or stale (no per-processing accuracy)
- DPIA absent for high-risk (article 45 triggers not assessed)
Indonesia PDP Data Subject Rights (Art 5-15)
Articles 5-15 of UU PDP grant Data Subjects 9 core rights. Article 5: right to obtain information regarding identity of Personal Data Controller + legal basis + purpose + accountability party representing Personal Data Controller. Article 6: right to receive + obtain complete information about personal data being processed + the processing carried out + the consequences of personal data processing. Article 7: right to update + correct errors or inaccuracies of personal data within a reasonable timeframe. Article 8: right to obtain access to personal data + receive copy. Article 9: right to terminate processing + delete + or destroy personal data subject to other applicable laws. Article 10: right to revoke consent. Article 11: right to object to decision-making actions based on automated processing including profiling that has legal effects or substantial similar effects on the Data Subj
- Data subject rights portal + 9 rights operationalised + intake + verification + records
- Response SLA 3 days + extension + written justification + records + statistics
- Identity verification + KTP + alternative documentation + records + audit
- Automated decision-making opt-out + profiling impact assessment + records
- Damages claim procedure + compensation + DPA complaint coordination + records
- Data subject rights portal absent (no intake mechanism)
- Response 3-day SLA missed (slow processing)
- Identity verification weak (impersonation risk)
- Automated decision-making not assessed (no opt-out)
- Damages claim procedure unclear (no compensation framework)
Indonesia PDP Enforcement + Sanctions (Art 57-73)
Articles 57-73 of UU PDP establish comprehensive enforcement and sanctions regime. Article 57 Administrative Sanctions: violations may result in (a) written warning; (b) temporary suspension of processing activities; (c) deletion or destruction of personal data; (d) administrative fine up to maximum 2 percent of annual revenue or annual receipts during preceding fiscal year (similar to GDPR Art 83 Tier 2 + India DPDP INR 200 crore for similar offences). Article 58 Lembaga PDP: separate Personal Data Protection Agency to be established by Presidential Regulation as an independent statutory body responsible for protection enforcement. Functions: (a) policy formulation + implementation oversight; (b) registration of Controllers/Processors/DPOs; (c) breach handling + complaint resolution; (d) inquiry + investigation + adjudication; (e) cooperation with international DPAs and DPA networks (e.
- Administrative sanctions risk assessment + 2pct revenue exposure + Board awareness + records
- Criminal sanctions awareness + individual/corporate + IDR 5-6 billion + records + counsel
- Lembaga PDP engagement + registration + cooperation + records + transitional Kemkominfo
- Damages claims + civil liability + class action exposure + insurance + records
- Compliance program + Board-level + penalty mitigation + records + monitoring
- Administrative sanctions not assessed (2pct revenue exposure unmanaged)
- Criminal sanctions not Board-level (individual leadership exposure not understood)
- Lembaga PDP not engaged (operating without registration where required)
- Civil damages unprepared (no insurance or counsel framework)
- Compliance program not Board-level (penalty mitigation absent)
Indonesia PDP Lawful Basis (Art 16-19)
Articles 16-19 of UU PDP establish the foundational lawful processing framework. Article 16: lawful basis for processing personal data limited to (a) explicit valid consent of the Data Subject for one or more specific purposes; (b) performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract; (c) fulfilment of legal obligations of the Data Controller; (d) protection of vital interests of the Data Subject; (e) performance of a task carried out in the public interest including for public services; (f) legitimate interests of the Data Controller or third parties (with balancing test). Six lawful bases parallel GDPR Art 6. Article 17 Notice: prior to obtaining personal data + Data Controller shall provide Data Subject with information regarding (a) legal basis for processing; (b) purposes for processing; (c
- Lawful basis matrix + per processing activity + 6 bases + records + Records of Processing
- Notice templates + Bahasa Indonesia + 8 elements + records + version control + accessibility
- Explicit consent capture + free/specific/informed/unambiguous + audit + records
- Purpose limitation procedure + compatibility test + new consent for incompatible + records
- Consent withdrawal mechanism + easy + processor cascade + records + 30-day SLA
- Lawful basis claimed as consent for all processing (no other basis assessed)
- Notice English-only or buried in Privacy Policy (not Bahasa or not accessible)
- Consent pre-ticked or bundled (violates explicit standard)
- Purpose limitation not enforced (any compatible purpose claimed)
- Withdrawal harder than giving consent (multi-step process)
Indonesia PDP Marketing + Profiling
Direct marketing + profiling + tracking technologies are subject to UU PDP consent + lawful basis requirements + Indonesian sectoral law overlays. (1) Direct Marketing: per Article 18 + general marketing communications require Data Subject opt-in consent + may rely on legitimate interests for non-electronic mail to existing customers with clear opt-out + each electronic marketing communication shall include unsubscribe/opt-out mechanism. (2) Profiling: any automated processing including profiling that has legal effects or substantial similar effects requires opt-out per Article 11 + Data Protection Impact Assessment per Article 45. (3) Cookies + Similar Tracking Technologies: per UU PDP + coordinated with UU ITE (Electronic Information and Transactions Law) + PP 71/2019 on Electronic System and Transaction Implementation - websites and apps must (a) provide notice of cookie use; (b) obta
- Marketing consent capture + Article 18 opt-in + opt-out mechanism + records
- Profiling DPIA + opt-out per Article 11 + legal/significant effect assessment + records
- Cookie banner + preference center + granular consent + withdrawal + records + audit
- Behavioural advertising consent + sensitive category restrictions + children protection + records
- Marketing preference center + all channels + frequency settings + records + customer access
- Marketing consent bundled with general consent (not separate opt-in)
- Profiling DPIA absent (automated decision-making not assessed)
- Cookie banner cookie wall or opt-in absent for non-essential
- Behavioural advertising on sensitive categories without explicit consent
- Marketing preference center absent (customers cannot manage)
Indonesia PDP Processor + Cross-Border (Art 51 + 56)
Articles 47-56 of UU PDP govern relationships with processors and cross-border transfers. Article 47-50 Personal Data Processor: Processor (Prosesor Data Pribadi) shall (a) process personal data based on instructions from Personal Data Controller; (b) implement TOMs equivalent to Controller; (c) not engage subprocessors without Controller written authorisation; (d) ensure persons processing personal data are bound by confidentiality obligations; (e) assist Controller in fulfilling Data Subject rights; (f) return or delete personal data at end of services; (g) maintain ROPA per Article 46. Article 51 Data Processing Agreement: contract between Controller and Processor shall be in writing + Bahasa Indonesia + cover (a) subject matter + duration + nature + purpose of processing; (b) types of personal data + categories of Data Subjects; (c) obligations + rights of Controller + Processor; (d)
- DPA with each processor + Bahasa Indonesia + Article 51 12 elements + records
- Subprocessor list + written authorisation + Controller notice + records
- Cross-border transfer assessment + mechanism per transfer (consent/adequacy/BCR/SCC) + records
- Indonesian Representative appointed + foreign Controller compliance + records
- Data localisation + OJK financial/PP 71-2019/BSSN sectoral compliance + records
- DPA in English-only (not Bahasa Indonesia)
- Subprocessor approval bypassed (cloud vendor substitution without notice)
- Cross-border transfer claimed under consent without informing of risks
- Indonesian Representative absent for foreign Controller
- Data localisation ignored for OJK/PP 71-2019 covered data
Indonesia PDP Scope + UU 27/2022
Indonesia Personal Data Protection Law (Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi, UU PDP) signed into law by President Joko Widodo on 17 October 2022 + published in the State Gazette of Indonesia + becoming Indonesia first comprehensive personal data protection law. 2-year transition period from publication: full enforceability from 17 October 2024 + entities had until that date to comply with administrative + security + organisational requirements. UU PDP comprises 76 Articles organised in 16 Chapters: Chapter I General Provisions (Art 1-3) + Chapter II Types of Personal Data (Art 4) + Chapter III Rights of Personal Data Subject (Art 5-15) + Chapter IV Processing of Personal Data (Art 16-19) + Chapter V Obligations of Personal Data Controller and Processor (Art 20-46) + Chapter VI Transfer of Personal Data (Art 55-56) + Chapter VII Administrative Sanctions (Art 5
- UU PDP applicability assessment + per scope category + records
- Personal data classification + general vs specific + sensitive inventory + records
- 16 chapters + 76 articles compliance matrix + records + implementation plan
- Pre-17 October 2024 readiness + post-effective compliance + records
- DPA engagement + Kemkominfo + Lembaga + transitional awareness + records
- UU PDP applicability not assessed for extraterritorial scope
- Specific (sensitive) personal data not inventoried separately
- Compliance matrix incomplete (chapters/articles not mapped)
- Post-17 October 2024 effective date missed (operating without compliance program)
- Engagement only with Kemkominfo (Lembaga PDP not tracked)
Indonesia PDP Security + Breach (Art 39 + 46)
Articles 39 + 46 of UU PDP establish security + breach notification obligations. Article 39: Personal Data Controller shall protect personal data processed through implementation of appropriate technical + organisational + and physical security measures + commensurate with the nature + scope + context + and purpose of processing + and risk to the rights and freedoms of the Data Subject. TOMs include but not limited to: (a) data security policies + procedures + standards; (b) encryption at rest + in transit + key management; (c) pseudonymisation where appropriate; (d) access control + identity and access management + multi-factor authentication; (e) network security + segmentation + firewalls + IDS/IPS; (f) endpoint protection + EDR + DLP; (g) secure software development lifecycle (SDLC); (h) vulnerability management + patching; (i) data backup + recovery + business continuity; (j) physic
- TOMs assessment + per Article 39 + risk-commensurate + ISO/NIST alignment + records
- DPA breach notification + 3x24 hours + content per Article 46 + records + drills
- Data subject breach notification + direct/public + records + statistics
- IR plan + BSSN coord + 24x7 SOC + detection/containment/eradication/recovery + records
- Breach register + all breaches + lessons learned + remediation tracking + records
- TOMs not commensurate with risk (one-size-fits-all)
- 3x24 hours missed (treating as informational only)
- Data subject notification skipped (only DPA notified)
- IR plan paper-only (no BSSN coord or tabletop)
- Breach register incomplete (only major incidents)
Indonesia PDP Sensitive + Children
Article 4 of UU PDP categorises personal data into General Personal Data and Specific Personal Data. Specific Personal Data (Sensitive) per Article 4(2) includes: (a) health data and information; (b) biometric data; (c) genetic data; (d) personal data related to crimes; (e) child data (under 17 years per Indonesian Children Protection Law); (f) personal financial data; (g) other data per legislation. Processing of Specific Personal Data requires elevated protections per Article 25 and Implementing Regulations including: (1) explicit consent of Data Subject or legal guardian for children; (2) heightened security safeguards including encryption + access controls + audit trails; (3) reduced retention period; (4) DPIA mandatory; (5) Data Protection Officer (DPO) involvement; (6) restricted further processing; (7) impact assessment for transfer. Article 25 Children Data: processing of persona
- Specific personal data inventory + 7 categories + per processing activity + records
- Children under 17 + verifiable parental consent + age verification + KTP/Children ID + records
- Health data + UU Health/Hospital/Medical coord + records + electronic health record compliance
- Biometric/genetic/crime/financial data + sectoral coord OJK/BI + records
- DPIA mandatory + DPO involvement + elevated security TOMs + records
- Specific personal data not inventoried separately (mixed with general)
- Children under 17 processed without verifiable parental consent
- Health data not coordinated with sectoral law (e.g. UU Health Law)
- Biometric/genetic data without elevated controls
- DPIA not mandatory for sensitive (treated as optional)
Indonesia PDP Training + Coord + Transition
Training + awareness + coordination operationalise UU PDP within Indonesia and across the regional + global regulatory landscape. Training and Awareness: mandatory cyber + privacy awareness training for all staff + role-specific training for IT + security + executives + Board + Bahasa Indonesia + records + KPIs + integration with national Cyber Surakshit Bharat-equivalent programs. ASEAN Data Protection Harmonisation: ASEAN Data Management Framework + ASEAN Model Contractual Clauses (MCCs) + ASEAN Framework on Personal Data Protection + ASEAN Smart Cities Network + ASEAN Information and Communications Technology Masterplan + Indonesia as one of 10 ASEAN members. Singapore PDPA: closest template influence + Indonesia PDP imitates many Singapore PDPA structural elements including breach notification + DPO appointment + DPA powers + cross-border consent. Coordination with: Malaysia PDPA + P
- Privacy awareness training + Bahasa Indonesia + role-based + records + KPIs
- ASEAN harmonisation + MCCs adoption + Singapore PDPA cross-mapping + records
- APEC CBPR participation + Privacy Enforcement Network engagement + records
- Cross-sectoral compliance + OJK/BI/BSSN/Kemkominfo + records + audit
- Lembaga PDP transition monitoring + Kemkominfo engagement + records + readiness
- Training English-only (not Bahasa Indonesia)
- ASEAN MCCs not adopted for cross-border (custom contracts only)
- APEC CBPR not pursued (regional cooperation missed)
- Cross-sectoral compliance fragmented (only Kemkominfo)
- Lembaga PDP transition unmonitored (no readiness for full enforcement)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Indonesia PDP Law framework page.