Indonesia
PDP Law
Personal Data Protection Law (Law 27 of 2022)
简要说明
Indonesia's PDP Law is a GDPR-inspired consent regime. Processing based on consent requires valid, explicit and informed consent recorded clearly, with stricter handling for specific categories of personal data.
地区
Indonesia
生效状态
Enacted 2022, transition through 2024
分类
亚洲与非洲
适用对象
Public and private data controllers and processors that process personal data of individuals in Indonesia, including those abroad with effects on people in Indonesia.
处罚
Administrative fines up to 2% of annual revenue, plus criminal penalties and corporate fines for unlawful collection or disclosure.
主要义务
- Obtain valid, explicit and recorded consent where it is the basis
- Provide clear notice of purpose and retention
- Honor access, correction, erasure and objection rights
- Appoint a data protection officer for certain processing
- Notify breaches to the authority and affected individuals within the required time
如何使用 ConsentX 满足 PDP Law 的要求
- 1
扫描您的网站
运行免费扫描,找出网站上的每一个 Cookie 和跟踪器,从而准确了解 PDP Law 下哪些内容需要取得同意。
- 2
展示按地区适配的同意横幅
添加 ConsentX 横幅。它会识别每位访问者的地区,并自动展示 PDP Law 所要求的同意流程。
- 3
在取得同意前拦截跟踪器
在访问者同意之前,持续拦截非必要的 Cookie 和跟踪器,确保同意前不会有任何加载。
- 4
记录防篡改凭证
每一次选择都会保存为防篡改的同意回执,可在 PDP Law 审计中提供。
- 5
按时处理数据主体请求
使用内置的 DSAR 工作流与 SLA 计时器,在法定期限内回应查阅、删除和退出请求。