Personal Data Protection Law, Law No. 27 of 2022
Indonesia
In force
Law No. 27 of 2022 was enacted and promulgated on 17 October 2022. The law provided a maximum two-year transition period for controllers, processors, and other parties involved in processing personal data to comply with the PDP Law.
Asia & Africa
The PDP Law applies broadly to individuals, public bodies, private organisations, companies, data controllers, data processors, and international organisations. The law can also apply to organisations outside Indonesia where their processing activities have legal consequences in Indonesia and/or affect Indonesian citizens outside Indonesian territory. This means an organisation does not necessarily avoid Indonesian privacy obligations simply because its business or systems are located outside Indonesia.
The PDP Law provides for both administrative and criminal sanctions. Administrative sanctions can include written warnings, temporary suspension of personal-data processing, deletion or destruction of personal data, and administrative fines. The maximum administrative fine is 2% of annual revenue or annual receipts attributable to the relevant violation, as provided by Article 57. The law also establishes criminal penalties for certain unlawful activities involving personal data, including unlawful acquisition, disclosure, use, or falsification. Corporate entities can also face corporate penalties under the law.
Indonesia's PDP Law is not a consent-only framework. It recognises six legal bases for processing personal data, and consent is one of them.
The PDP Law divides personal data into two broad categories.
Specific personal data includes:
General personal data includes:
The distinction is important because specific personal data can create greater risks for individuals and may therefore require additional safeguards.
Indonesia's PDP Law requires a data controller to have a legal basis for processing personal data.
Article 20 identifies six legal bases:
Therefore, organisations should not automatically treat consent as the legal basis for every processing activity.
Where consent is used as the legal basis, the PDP Law establishes specific requirements.
Consent must be:
Consent may be provided in written or recorded form and can be submitted electronically or non-electronically.
Where consent covers additional purposes, the request must be clearly distinguishable, accessible, and written in simple and clear language.
The controller must also be able to demonstrate evidence of the consent obtained. This makes consent records and audit trails particularly important for organisations relying on consent as a legal basis.
Individuals have the right to withdraw consent for processing.
When a data subject withdraws consent, the controller must stop processing based on that consent within 3 × 24 hours of receiving the withdrawal request, subject to the law and applicable circumstances.
ConsentX can help organisations record the original consent, capture withdrawal requests, and maintain evidence of the resulting preference change.
Where processing is based on consent, organisations must provide information including:
If this information changes, the data subject must be informed before the change takes effect.
Privacy notices should therefore be clear, accessible, and sufficiently specific to explain how personal data will be handled.
The PDP Law establishes several core principles for processing personal data.
Personal data must be processed:
The law also requires personal data to be deleted or destroyed after the retention period expires or when applicable circumstances require deletion or destruction.
The PDP Law provides individuals with a broad set of rights relating to their personal data.
These include rights relating to:
The law also establishes specific response requirements for certain requests. For example, access requests must generally be addressed within 3 × 24 hours from receipt, subject to the statutory provisions and exceptions.
Controllers must ensure that personal data is accurate, complete, and consistent.
Where an individual requests an update or correction, the controller must generally make the necessary correction within 3 × 24 hours of receiving the request and notify the individual of the result.
This creates an important operational requirement for organisations handling large volumes of customer or employee information.
The PDP Law establishes circumstances in which personal data must be deleted or destroyed.
A controller must delete personal data where, among other circumstances:
The law separately addresses destruction, including where the applicable retention period has expired or where destruction is requested and permitted under the law.
ConsentX can support structured privacy-request workflows for organisations that need to manage deletion and other data-subject requests.
The PDP Law provides specific protection for children's personal data.
Processing children's personal data must be carried out in accordance with applicable requirements and requires consent from the child's parent and/or guardian where consent is required under the law.
Organisations providing websites, applications, educational services, gaming platforms, or other services likely to be used by children should therefore assess their age-related privacy controls.
Indonesia's PDP Law does not use exactly the same terminology as the GDPR's “special categories of personal data”.
Instead, it identifies specific personal data, including:
Processing activities involving these categories can also trigger additional risk-management requirements.
Controllers must conduct a Data Protection Impact Assessment where processing creates a high level of risk to data subjects.
High-risk processing identified by the PDP Law includes:
The law provides that further requirements for DPIAs are to be established through implementing regulations.
Organisations using AI, profiling, biometrics, large-scale analytics, or other high-risk technologies should therefore include privacy impact assessment within their compliance programme.
Controllers must protect personal data through appropriate technical and operational measures.
The PDP Law requires controllers to:
Security controls should therefore be proportionate to the nature and risk of the processing activity.
One of the most important operational requirements under Indonesia's PDP Law concerns personal-data breaches.
In the event of a failure in personal-data protection, the controller must provide written notification no later than 3 × 24 hours to:
The notification must include, at minimum:
In certain circumstances, public notification may also be required.
Organisations should therefore maintain an incident-response process capable of rapidly identifying affected data, individuals, systems, and remediation measures.
The PDP Law requires controllers and processors to appoint a person responsible for data-protection functions in specified circumstances.
This applies where:
The person performing the data-protection function should have appropriate professionalism, legal and privacy knowledge, and the ability to perform the required responsibilities. They may be internal or external to the organisation.
The PDP Law distinguishes between two roles.
Data controller. The party that determines the purposes and means of processing personal data.
Data processor. The party that processes personal data on behalf of a controller.
Controllers remain responsible for ensuring that processing activities comply with the PDP Law and must supervise parties involved in processing under their control.
Organisations should therefore assess privacy obligations throughout their vendor and processor ecosystem.
The PDP Law permits transfers of personal data outside Indonesia, but establishes a hierarchy of safeguards.
A controller transferring personal data outside Indonesia must generally ensure that:
Further requirements for international transfers are to be established through implementing regulations.
Organisations using international cloud providers, analytics services, advertising platforms, SaaS applications, or other overseas vendors should therefore document their transfer arrangements and safeguards.
Indonesia's PDP Law does not operate as a standalone cookie-consent law requiring consent for every cookie.
However, cookies, pixels, analytics tools, advertising technologies, and other tracking technologies may involve the processing of personal data.
Organisations should therefore assess:
Where consent is relied upon, the consent mechanism should meet the PDP Law's requirements for valid, explicit, informed, and recorded consent.
ConsentX can help organisations identify website trackers, configure consent controls, block non-essential technologies where required, and maintain evidence of user choices.
The PDP Law does not make consent the universal legal basis for all marketing activity.
Organisations should identify the appropriate legal basis for processing personal data used in:
Where consent is relied upon, organisations should ensure that the consent request clearly identifies the relevant purpose and is separately distinguishable where multiple purposes are presented.
Consent records should also be retained as evidence.
The PDP Law identifies automated decision-making that produces legal consequences or significant impacts on individuals as a form of high-risk processing.
This can trigger the requirement to conduct a Data Protection Impact Assessment.
Organisations using the following should assess whether their processing falls within the law's high-risk categories and ensure appropriate transparency and safeguards:
The PDP Law provides for a dedicated institution responsible for:
As of 2026, the Indonesian government has been working toward establishing an independent Personal Data Protection Authority. In July 2026, the Ministry of Communication and Digital Affairs stated that the government was finalising the establishment of the authority and the related presidential regulation.
Organisations should therefore monitor further regulatory developments concerning the final institutional framework and implementing regulations.
Indonesia continues to develop the implementing framework supporting Law No. 27 of 2022.
The Ministry of Communication and Digital Affairs has been working on implementing regulations covering areas including:
In 2025, the Ministry reported that a draft government regulation implementing the PDP Law was undergoing harmonisation.
Organisations should therefore distinguish between requirements already established directly by the PDP Law and detailed requirements that depend on implementing regulations.
Capture explicit consent where consent is selected as the legal basis for processing.
Present separate and understandable consent choices for different processing purposes rather than relying on unclear bundled consent.
Maintain evidence of consent, including the context in which the user made the choice, to support the controller's obligation to demonstrate consent.
Display clear information about the purpose and nature of processing at relevant collection points.
Prevent non-essential cookies, pixels, analytics, and advertising technologies from firing before the required consent or preference decision.
Capture withdrawal requests and support the operational workflow for stopping consent-based processing.
Manage access, correction, deletion, objection, and other applicable data-subject requests through a structured workflow.
Maintain a central record of consent and preference events to support audits and internal compliance reviews.
Apply Indonesia-specific consent and privacy configurations alongside requirements from other countries.
Support clear communication around third-party services and international data-processing activities.
Indonesia's PDP Law requires more than simply placing a cookie banner on a website. ConsentX helps organisations operationalise privacy compliance through explicit consent management, purpose-based consent, privacy and collection notices, prior-script blocking, consent records, consent withdrawal, data-subject request workflows, audit evidence, regional privacy rules, and third-party tracking controls. Build a transparent and audit-ready privacy experience for users in Indonesia with ConsentX. Get started with ConsentX or book a demo to see how ConsentX can support your global privacy compliance programme.
This page provides a general, plain-English overview of Indonesia's Personal Data Protection Law (Law No. 27 of 2022) and related compliance requirements. It is not legal advice and does not cover every sector-specific requirement, exemption, implementing regulation, regulatory interpretation, or individual compliance circumstance. Organisations should review the current Indonesian legislation and regulatory guidance and obtain qualified Indonesian legal advice where necessary.
Run a privacy scan to identify:
Identify where personal data is collected across:
For every processing activity, determine which of the six legal bases under the PDP Law applies.
Do not automatically use consent when another lawful basis is more appropriate.
Where consent is the legal basis, configure a clear consent experience that identifies:
Avoid unclear bundled consent.
Where multiple purposes are involved, provide clearly distinguishable choices that are understandable and accessible.
Use prior-script blocking to prevent non-essential tracking technologies from operating before the applicable consent decision.
Store consent records that demonstrate:
Provide a mechanism for individuals to change or withdraw consent and route the request to the relevant processing systems.
Create a structured workflow for:
Identify vendors and processors located outside Indonesia and document the applicable transfer mechanism and safeguards.
Maintain incident-response procedures capable of supporting the PDP Law's 3 × 24-hour notification requirement where applicable.
Conduct DPIAs for processing activities that may create high risks, including large-scale processing, specific personal data, systematic monitoring, automated decision-making, data matching, and new technologies.