Indonesia
PDP Law
Personal Data Protection Law (Law 27 of 2022)
要点
Indonesia's PDP Law is a GDPR-inspired consent regime. Processing based on consent requires valid, explicit and informed consent recorded clearly, with stricter handling for specific categories of personal data.
地域
Indonesia
施行状況
Enacted 2022, transition through 2024
分類
アジア・アフリカ
遵守が必要な事業者
Public and private data controllers and processors that process personal data of individuals in Indonesia, including those abroad with effects on people in Indonesia.
制裁
Administrative fines up to 2% of annual revenue, plus criminal penalties and corporate fines for unlawful collection or disclosure.
主な義務
- Obtain valid, explicit and recorded consent where it is the basis
- Provide clear notice of purpose and retention
- Honor access, correction, erasure and objection rights
- Appoint a data protection officer for certain processing
- Notify breaches to the authority and affected individuals within the required time
ConsentX で PDP Law に対応する方法
- 1
サイトをスキャンする
無料スキャンでサイト上のすべての Cookie とトラッカーを検出し、PDP Law の下で何に同意が必要かを正確に把握します。
- 2
地域を判定する同意バナーを表示する
ConsentX のバナーを設置します。訪問者の地域を検出し、PDP Law が求める同意の体験を自動的に表示します。
- 3
同意まではトラッカーをブロックする
訪問者が同意するまで、必須でない Cookie とトラッカーをブロックしたままにし、同意前には何も発火しないようにします。
- 4
改ざん検知可能な証跡を記録する
すべての選択は改ざん検知可能な同意レシートとして保存され、PDP Law の監査で提示できます。
- 5
データ主体の請求に期限内に対応する
SLA タイマー付きの DSAR ワークフローを使い、開示、削除、オプトアウトの請求に法定期限内に回答します。