DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Indonesia

Indonesia PDP Law Compliance with ConsentX

Personal Data Protection Law, Law No. 27 of 2022

Indonesia's Personal Data Protection Law (PDP Law), Law No. 27 of 2022, is the country's comprehensive framework governing the processing and protection of personal data. The law establishes requirements for data controllers (Pengendali Data Pribadi) and data processors (Prosesor Data Pribadi), defines individual rights, regulates consent and other lawful bases for processing, establishes obligations for security and privacy governance, regulates cross-border data transfers, and provides administrative and criminal sanctions for violations. The law was enacted on 17 October 2022 and provided a two-year transition period for organisations to bring their processing activities into compliance. Unlike a consent-only framework, Indonesia's PDP Law recognises six legal bases for processing personal data. Consent is one of these bases and must meet specific requirements when relied upon.
Region

Indonesia

Status

In force

Law No. 27 of 2022 was enacted and promulgated on 17 October 2022. The law provided a maximum two-year transition period for controllers, processors, and other parties involved in processing personal data to comply with the PDP Law.

Group

Asia & Africa

Who Must Comply With Indonesia's PDP Law?

The PDP Law applies broadly to individuals, public bodies, private organisations, companies, data controllers, data processors, and international organisations. The law can also apply to organisations outside Indonesia where their processing activities have legal consequences in Indonesia and/or affect Indonesian citizens outside Indonesian territory. This means an organisation does not necessarily avoid Indonesian privacy obligations simply because its business or systems are located outside Indonesia.

Penalties Under Indonesia's PDP Law

The PDP Law provides for both administrative and criminal sanctions. Administrative sanctions can include written warnings, temporary suspension of personal-data processing, deletion or destruction of personal data, and administrative fines. The maximum administrative fine is 2% of annual revenue or annual receipts attributable to the relevant violation, as provided by Article 57. The law also establishes criminal penalties for certain unlawful activities involving personal data, including unlawful acquisition, disclosure, use, or falsification. Corporate entities can also face corporate penalties under the law.

In Short

  • Have a valid legal basis for processing personal data.
  • Obtain valid, explicit consent where consent is the chosen legal basis.
  • Provide appropriate information about processing activities.
  • Process data only for specified and lawful purposes.
  • Protect personal data against unauthorised access, disclosure, alteration, misuse, destruction, or loss.
  • Respect data-subject rights, including access, correction, deletion, withdrawal of consent, and objection or restriction rights where applicable.
  • Notify personal-data breaches within the statutory timeframe.
  • Conduct a Data Protection Impact Assessment (DPIA) for certain high-risk processing.
  • Appoint a person responsible for data-protection functions in specified circumstances.
  • Meet requirements for transfers of personal data outside Indonesia.
  • Maintain accountability and evidence of compliance.

Indonesia's PDP Law is not a consent-only framework. It recognises six legal bases for processing personal data, and consent is one of them.

What Data Is Covered?

The PDP Law divides personal data into two broad categories.

Specific personal data includes:

  • Health and medical information
  • Biometric data
  • Genetic data
  • Criminal records
  • Children's data
  • Personal financial data
  • Other categories designated by applicable regulations

General personal data includes:

  • Full name
  • Gender
  • Nationality
  • Religion
  • Marital status
  • Personal data combined with other information that can identify an individual

The distinction is important because specific personal data can create greater risks for individuals and may therefore require additional safeguards.

Legal Bases for Processing Personal Data

Indonesia's PDP Law requires a data controller to have a legal basis for processing personal data.

Article 20 identifies six legal bases:

  • Explicit and valid consent for one or more specific purposes communicated to the individual.
  • Contractual necessity, including processing necessary to perform a contract or fulfil a request before entering into a contract.
  • Legal obligation of the controller.
  • Vital interests of the data subject.
  • Public interest, public service, or exercise of official authority under applicable law.
  • Legitimate interests, taking into account the purpose, necessity, balance of interests, and rights of the data subject.

Therefore, organisations should not automatically treat consent as the legal basis for every processing activity.

Consent Requirements Under Indonesia's PDP Law

Where consent is used as the legal basis, the PDP Law establishes specific requirements.

Consent must be:

  • Valid
  • Explicit
  • Related to one or more specific purposes
  • Properly recorded
  • Based on information provided to the data subject
  • Understandable
  • Clearly distinguishable from other matters where multiple purposes are involved

Consent may be provided in written or recorded form and can be submitted electronically or non-electronically.

Where consent covers additional purposes, the request must be clearly distinguishable, accessible, and written in simple and clear language.

The controller must also be able to demonstrate evidence of the consent obtained. This makes consent records and audit trails particularly important for organisations relying on consent as a legal basis.

Consent Withdrawal

Individuals have the right to withdraw consent for processing.

When a data subject withdraws consent, the controller must stop processing based on that consent within 3 × 24 hours of receiving the withdrawal request, subject to the law and applicable circumstances.

ConsentX can help organisations record the original consent, capture withdrawal requests, and maintain evidence of the resulting preference change.

Privacy Notices and Transparency

Where processing is based on consent, organisations must provide information including:

  • The legal basis for processing
  • The purpose of processing
  • The types and relevance of personal data being processed
  • The retention period for documents containing personal data
  • Details of the information collected
  • The processing period
  • The rights of the data subject

If this information changes, the data subject must be informed before the change takes effect.

Privacy notices should therefore be clear, accessible, and sufficiently specific to explain how personal data will be handled.

Data Processing Principles

The PDP Law establishes several core principles for processing personal data.

Personal data must be processed:

  • In a limited and specific manner
  • Lawfully
  • Transparently
  • For specified purposes
  • With respect for data-subject rights
  • Accurately and completely
  • In a current and accountable manner
  • With appropriate security safeguards
  • With appropriate confidentiality
  • In accordance with applicable retention requirements

The law also requires personal data to be deleted or destroyed after the retention period expires or when applicable circumstances require deletion or destruction.

Data Subject Rights Under the PDP Law

The PDP Law provides individuals with a broad set of rights relating to their personal data.

These include rights relating to:

  • Information about processing
  • Access to personal data
  • Correction and updating
  • Deletion or destruction
  • Withdrawal of consent
  • Restriction or suspension of processing
  • Objecting to certain processing activities
  • Data portability
  • Compensation for violations
  • Rights relating to automated decision-making in applicable circumstances

The law also establishes specific response requirements for certain requests. For example, access requests must generally be addressed within 3 × 24 hours from receipt, subject to the statutory provisions and exceptions.

Data Accuracy and Correction

Controllers must ensure that personal data is accurate, complete, and consistent.

Where an individual requests an update or correction, the controller must generally make the necessary correction within 3 × 24 hours of receiving the request and notify the individual of the result.

This creates an important operational requirement for organisations handling large volumes of customer or employee information.

Deletion and Destruction of Personal Data

The PDP Law establishes circumstances in which personal data must be deleted or destroyed.

A controller must delete personal data where, among other circumstances:

  • The data is no longer necessary for the processing purpose.
  • The data subject withdraws consent where consent is the applicable basis.
  • The data subject requests deletion.
  • The personal data was obtained or processed unlawfully.

The law separately addresses destruction, including where the applicable retention period has expired or where destruction is requested and permitted under the law.

ConsentX can support structured privacy-request workflows for organisations that need to manage deletion and other data-subject requests.

Children's Personal Data

The PDP Law provides specific protection for children's personal data.

Processing children's personal data must be carried out in accordance with applicable requirements and requires consent from the child's parent and/or guardian where consent is required under the law.

Organisations providing websites, applications, educational services, gaming platforms, or other services likely to be used by children should therefore assess their age-related privacy controls.

Sensitive and High-Risk Personal Data

Indonesia's PDP Law does not use exactly the same terminology as the GDPR's “special categories of personal data”.

Instead, it identifies specific personal data, including:

  • Health information
  • Biometric information
  • Genetic information
  • Criminal records
  • Children's data
  • Personal financial data

Processing activities involving these categories can also trigger additional risk-management requirements.

Data Protection Impact Assessment (DPIA)

Controllers must conduct a Data Protection Impact Assessment where processing creates a high level of risk to data subjects.

High-risk processing identified by the PDP Law includes:

  • Automated decision-making producing legal or significant effects
  • Processing specific personal data
  • Large-scale processing
  • Systematic evaluation, scoring, or monitoring
  • Matching or combining groups of data
  • Use of new technologies
  • Processing that restricts the exercise of data-subject rights

The law provides that further requirements for DPIAs are to be established through implementing regulations.

Organisations using AI, profiling, biometrics, large-scale analytics, or other high-risk technologies should therefore include privacy impact assessment within their compliance programme.

Data Security Obligations

Controllers must protect personal data through appropriate technical and operational measures.

The PDP Law requires controllers to:

  • Protect personal data against unlawful processing.
  • Prevent unauthorised access.
  • Maintain appropriate security systems.
  • Determine an appropriate level of security based on the nature and risk of the personal data.
  • Maintain confidentiality.
  • Monitor parties involved in processing under their control.

Security controls should therefore be proportionate to the nature and risk of the processing activity.

Personal Data Breach Notification

One of the most important operational requirements under Indonesia's PDP Law concerns personal-data breaches.

In the event of a failure in personal-data protection, the controller must provide written notification no later than 3 × 24 hours to:

  • The affected data subject
  • The relevant supervisory authority

The notification must include, at minimum:

  • The personal data affected or exposed
  • When and how the personal data was exposed
  • Measures taken by the controller to address and recover from the incident

In certain circumstances, public notification may also be required.

Organisations should therefore maintain an incident-response process capable of rapidly identifying affected data, individuals, systems, and remediation measures.

Data Protection Officer and the PDP Function

The PDP Law requires controllers and processors to appoint a person responsible for data-protection functions in specified circumstances.

This applies where:

  • Personal data is processed for public-service purposes.
  • The controller's core activities involve regular and systematic monitoring of personal data on a large scale.
  • The controller's core activities involve large-scale processing of specific personal data and/or personal data relating to criminal acts.

The person performing the data-protection function should have appropriate professionalism, legal and privacy knowledge, and the ability to perform the required responsibilities. They may be internal or external to the organisation.

Processor and Controller Responsibilities

The PDP Law distinguishes between two roles.

Data controller. The party that determines the purposes and means of processing personal data.

Data processor. The party that processes personal data on behalf of a controller.

Controllers remain responsible for ensuring that processing activities comply with the PDP Law and must supervise parties involved in processing under their control.

Organisations should therefore assess privacy obligations throughout their vendor and processor ecosystem.

Cross-Border Data Transfers

The PDP Law permits transfers of personal data outside Indonesia, but establishes a hierarchy of safeguards.

A controller transferring personal data outside Indonesia must generally ensure that:

  • The destination country provides a level of personal-data protection equal to or higher than the protection under Indonesia's PDP Law; or
  • Where that condition is not met, the controller provides adequate and binding protection; or
  • Where neither condition is satisfied, the controller obtains the consent of the data subject.

Further requirements for international transfers are to be established through implementing regulations.

Organisations using international cloud providers, analytics services, advertising platforms, SaaS applications, or other overseas vendors should therefore document their transfer arrangements and safeguards.

Cookies and Online Tracking

Indonesia's PDP Law does not operate as a standalone cookie-consent law requiring consent for every cookie.

However, cookies, pixels, analytics tools, advertising technologies, and other tracking technologies may involve the processing of personal data.

Organisations should therefore assess:

  • What information the technology collects
  • Whether individuals can be identified directly or indirectly
  • The purpose of collection
  • The applicable legal basis
  • Whether consent is required or selected as the legal basis
  • Whether information is disclosed to third parties
  • Whether information is transferred outside Indonesia
  • How long the information is retained

Where consent is relied upon, the consent mechanism should meet the PDP Law's requirements for valid, explicit, informed, and recorded consent.

ConsentX can help organisations identify website trackers, configure consent controls, block non-essential technologies where required, and maintain evidence of user choices.

Direct Marketing and Consent

The PDP Law does not make consent the universal legal basis for all marketing activity.

Organisations should identify the appropriate legal basis for processing personal data used in:

  • Email marketing
  • SMS marketing
  • Advertising
  • Personalised campaigns
  • Customer profiling
  • Remarketing
  • Audience segmentation

Where consent is relied upon, organisations should ensure that the consent request clearly identifies the relevant purpose and is separately distinguishable where multiple purposes are presented.

Consent records should also be retained as evidence.

Automated Decision-Making and Profiling

The PDP Law identifies automated decision-making that produces legal consequences or significant impacts on individuals as a form of high-risk processing.

This can trigger the requirement to conduct a Data Protection Impact Assessment.

Organisations using the following should assess whether their processing falls within the law's high-risk categories and ensure appropriate transparency and safeguards:

  • AI-based decision systems
  • Automated scoring
  • Profiling
  • Fraud detection
  • Credit assessment
  • Behavioural analysis
  • Automated eligibility decisions

Supervisory Authority

The PDP Law provides for a dedicated institution responsible for:

  • Developing personal-data protection policy and strategy
  • Supervising personal-data processing
  • Enforcing administrative law
  • Facilitating out-of-court dispute resolution

As of 2026, the Indonesian government has been working toward establishing an independent Personal Data Protection Authority. In July 2026, the Ministry of Communication and Digital Affairs stated that the government was finalising the establishment of the authority and the related presidential regulation.

Organisations should therefore monitor further regulatory developments concerning the final institutional framework and implementing regulations.

Current Implementation and Regulatory Developments

Indonesia continues to develop the implementing framework supporting Law No. 27 of 2022.

The Ministry of Communication and Digital Affairs has been working on implementing regulations covering areas including:

  • Personal-data processing
  • Data protection governance
  • Cybersecurity
  • Emerging technologies
  • International data transfers
  • DPIA requirements
  • Administrative enforcement

In 2025, the Ministry reported that a draft government regulation implementing the PDP Law was undergoing harmonisation.

Organisations should therefore distinguish between requirements already established directly by the PDP Law and detailed requirements that depend on implementing regulations.

How ConsentX Helps With Indonesia PDP Law Compliance

Explicit consent management

Capture explicit consent where consent is selected as the legal basis for processing.

Purpose-based consent

Present separate and understandable consent choices for different processing purposes rather than relying on unclear bundled consent.

Consent records

Maintain evidence of consent, including the context in which the user made the choice, to support the controller's obligation to demonstrate consent.

Privacy and collection notices

Display clear information about the purpose and nature of processing at relevant collection points.

Prior-script blocking

Prevent non-essential cookies, pixels, analytics, and advertising technologies from firing before the required consent or preference decision.

Consent withdrawal

Capture withdrawal requests and support the operational workflow for stopping consent-based processing.

DSAR and privacy requests

Manage access, correction, deletion, objection, and other applicable data-subject requests through a structured workflow.

Consent audit evidence

Maintain a central record of consent and preference events to support audits and internal compliance reviews.

Regional rule management

Apply Indonesia-specific consent and privacy configurations alongside requirements from other countries.

Cross-border transparency

Support clear communication around third-party services and international data-processing activities.

Indonesia PDP Law Compliance With ConsentX

Indonesia's PDP Law requires more than simply placing a cookie banner on a website. ConsentX helps organisations operationalise privacy compliance through explicit consent management, purpose-based consent, privacy and collection notices, prior-script blocking, consent records, consent withdrawal, data-subject request workflows, audit evidence, regional privacy rules, and third-party tracking controls. Build a transparent and audit-ready privacy experience for users in Indonesia with ConsentX. Get started with ConsentX or book a demo to see how ConsentX can support your global privacy compliance programme.

This page provides a general, plain-English overview of Indonesia's Personal Data Protection Law (Law No. 27 of 2022) and related compliance requirements. It is not legal advice and does not cover every sector-specific requirement, exemption, implementing regulation, regulatory interpretation, or individual compliance circumstance. Organisations should review the current Indonesian legislation and regulatory guidance and obtain qualified Indonesian legal advice where necessary.

How to Comply With Indonesia's PDP Law Using ConsentX

  1. 1

    Scan your website

    Run a privacy scan to identify:

    • Cookies
    • Analytics
    • Advertising trackers
    • Pixels
    • Tags
    • Embedded third-party services
    • Forms
    • Other technologies that may process personal data
  2. 2

    Map personal data collection

    Identify where personal data is collected across:

    • Registration
    • Login
    • Contact forms
    • Checkout
    • Newsletter subscriptions
    • Customer support
    • Analytics
    • Advertising
    • Mobile and web applications
  3. 3

    Identify the legal basis

    For every processing activity, determine which of the six legal bases under the PDP Law applies.

    Do not automatically use consent when another lawful basis is more appropriate.

  4. 4

    Configure explicit consent

    Where consent is the legal basis, configure a clear consent experience that identifies:

    • Purpose
    • Data involved
    • Processing period
    • Retention information
    • Applicable rights
  5. 5

    Separate different purposes

    Avoid unclear bundled consent.

    Where multiple purposes are involved, provide clearly distinguishable choices that are understandable and accessible.

  6. 6

    Block non-essential trackers

    Use prior-script blocking to prevent non-essential tracking technologies from operating before the applicable consent decision.

  7. 7

    Record consent evidence

    Store consent records that demonstrate:

    • What the individual was told
    • Which purpose was presented
    • What choice was made
    • When the choice was made
    • How the choice can be withdrawn
  8. 8

    Manage consent withdrawal

    Provide a mechanism for individuals to change or withdraw consent and route the request to the relevant processing systems.

  9. 9

    Manage data-subject requests

    Create a structured workflow for:

    • Access
    • Correction
    • Deletion
    • Restriction
    • Objection
    • Consent withdrawal
    • Other applicable privacy requests
  10. 10

    Review international transfers

    Identify vendors and processors located outside Indonesia and document the applicable transfer mechanism and safeguards.

  11. 11

    Prepare for data breaches

    Maintain incident-response procedures capable of supporting the PDP Law's 3 × 24-hour notification requirement where applicable.

  12. 12

    Assess high-risk processing

    Conduct DPIAs for processing activities that may create high risks, including large-scale processing, specific personal data, systematic monitoring, automated decision-making, data matching, and new technologies.

Pertanyaan yang sering diajukan