PDP Law Compliance Check
Sixteen yes/no questions that map your organisation's readiness for Indonesia's Law No. 27/2022 on Personal Data Protection (PDP Law): governance, data subject rights, security, and third parties. Results and next steps appear instantly.
- 16 questions
- ± 8 minutes
Frequently asked questions
Since when has the PDP Law been fully in force in Indonesia?
Law No. 27 of 2022 on Personal Data Protection was enacted in October 2022 with a two-year compliance transition period for existing data controllers, with enforcement running since that transition period ended.
Does the PDP Law apply to companies based outside Indonesia?
Yes. The PDP Law also applies to any person, public body, or international organisation outside Indonesia's jurisdiction that processes the personal data of Indonesian citizens and has legal effect in Indonesia.
What sanctions apply for non-compliance?
Administrative sanctions such as written warnings, temporary suspension of processing, deletion or destruction of data, and administrative fines, plus criminal sanctions for the responsible individual in certain violations.
What is the difference between a data controller and a data processor?
A data controller determines the purpose and means of processing personal data. A data processor processes personal data on behalf of, and per the instructions of, the controller. Each carries different obligations under the PDP Law.
Who should complete this questionnaire?
The data protection officer (PIC PDP), a legal or compliance officer, or the head of IT who understands how personal data flows through the organisation.
Discuss PDP Law compliance with our consultants
We support you from gap analysis and building a RoPA and DPIA through to appointing a data protection officer.